File _patchinfo of Package patchinfo.6177

<patchinfo incident="6177">
  <packager>adrianSuSE</packager>
  <issue tracker="bnc" id="665768">VUL-0: build: cpio directory traversal</issue>
  <issue tracker="bnc" id="1069904">VUL-0: EMBARGOED: CVE-2017-14804: build: Exploit extractbuild to write to files in the host system</issue>
  <issue tracker="bnc" id="938556">VUL-0: CVE-2017-9274: osc executes spec code during "osc commit"</issue>
  <issue tracker="bnc" id="1059858">[source_validator] Cannot SR package gnu-compilers-hpc from openSUSE:Factory fo SUSE:SLE-15:GA</issue>
  <issue tracker="cve" id="2017-14804"></issue>
  <issue tracker="cve" id="2017-9274"></issue>
  <issue tracker="cve" id="2010-4226"></issue>
  <issue tracker="fate" id="323217"></issue>
  <issue tracker="bnc" id="1061500">osc is missing an install dependency on ca-certificates</issue>
  <category>security</category>
  <rating>important</rating>
  <summary>Fixing security issues on OBS toolchain</summary>
  <description>This OBS toolchain update fixes the following issues:

Package 'build':

- CVE-2010-4226: force use of bsdtar for VMs (bnc#665768)
- CVE-2017-14804: Improve file name check extractbuild (bsc#1069904)
- switch baselibs scheme for debuginfo packages from foo-debuginfo-32bit to foo-32bit-debuginfo (fate#323217)

Package 'obs-service-source_validator':
- CVE-2017-9274: Don't use rpmbuild to extract sources, patches etc. from a spec (bnc#938556).
- Update to version 0.7
- use spec_query instead of output_versions using the specfile parser from the build package (boo#1059858)

Package 'osc':
- update to version 0.162.0
- add Recommends: ca-certificates to enable TLS verification without manually installing them. (bnc#1061500)
</description>
</patchinfo>
openSUSE Build Service is sponsored by