FlawAtlas
Search the atlas
SUSE-SU-2015:0863-1 Not scored

Security update for SUSE Studio

This update provides SUSE Studio 1.3.10, including Amazon's EC2 support for SUSE Linux Enterprise 12 appliances. Additionally, the update includes fixes for the following issues: * #904372 - Arbitrary file existence disclosure in sprockets gem (CVE-2014-7819) * #904375 - Arbitrary file existence disclosure in Action Pack gem (CVE-2014-7818) * #918203 - Arbitrary file existence disclosure in Studio Onsite (CVE-2014-7829) * #852794 - SLES 11-SP3 templates fail to build x86_64 EC2 images * #914765 - Change of appliance name is not displayed in appliance's change log * #887893 - Change log not accessible via API * #918239 - Failure to create new appliances after upgrade to Studio Onsite 1.3.9 * #918395 - Remove 32bit as target for building EC2 appliances * #912512 - Studio doesn't allow duplicated repositories * #880078 - Studio packages contain files that get modified (by Studio) after installation. * #919037 - Can't open appliance on Gallery: undefined restructure_unsupportable_packages method. Security Issues: * CVE-2014-7819 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7819> * CVE-2014-7818 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7818> * CVE-2014-7829 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7829>

Exploit probability Not scored
Published May 5, 2015
Required by Not available
Last source change February 4, 2026

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2015:0863-1

This update provides SUSE Studio 1.3.10, including Amazon's EC2 support for SUSE Linux Enterprise 12 appliances. Additionally, the update includes fixes for the following issues: * #904372 - Arbitrary file existence disclosure in sprockets gem (CVE-2014-7819) * #904375 - Arbitrary file existence disclosure in Action Pack gem (CVE-2014-7818) * #918203 - Arbitrary file existence disclosure in Studio Onsite (CVE-2014-7829) * #852794 - SLES 11-SP3 templates fail to build x86_64 EC2 images * #914765 - Change of appliance name is not displayed in appliance's change log * #887893 - Change log not accessible via API * #918239 - Failure to create new appliances after upgrade to Studio Onsite 1.3.9 * #918395 - Remove 32bit as target for building EC2 appliances * #912512 - Studio doesn't allow duplicated repositories * #880078 - Studio packages contain files that get modified (by Studio) after installation. * #919037 - Can't open appliance on Gallery: undefined restructure_unsupportable_packages method. Security Issues: * CVE-2014-7819 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7819> * CVE-2014-7818 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7818> * CVE-2014-7829 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7829>

View original source

05 / REFERENCES

Further evidence