<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Security update for SUSE Studio</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>SUSE-SU-2015:0863-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2015-05-05T23:49:58Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2015-05-05T23:49:58Z</InitialReleaseDate>
    <CurrentReleaseDate>2015-05-05T23:49:58Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for SUSE Studio</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">
This update provides SUSE Studio 1.3.10, including Amazon's EC2 support for 
SUSE Linux Enterprise 12 appliances.

Additionally, the update includes fixes for the following issues:

    * #904372 - Arbitrary file existence disclosure in sprockets gem
      (CVE-2014-7819)
    * #904375 - Arbitrary file existence disclosure in Action Pack gem
      (CVE-2014-7818)
    * #918203 - Arbitrary file existence disclosure in Studio Onsite
      (CVE-2014-7829)
    * #852794 - SLES 11-SP3 templates fail to build x86_64 EC2 images
    * #914765 - Change of appliance name is not displayed in appliance's
      change log
    * #887893 - Change log not accessible via API
    * #918239 - Failure to create new appliances after upgrade to Studio
      Onsite 1.3.9
    * #918395 - Remove 32bit as target for building EC2 appliances
    * #912512 - Studio doesn't allow duplicated repositories
    * #880078 - Studio packages contain files that get modified (by Studio)
      after installation.
    * #919037 - Can't open appliance on Gallery: undefined
      restructure_unsupportable_packages method.

Security Issues:

    * CVE-2014-7819
      &lt;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7819&gt;
    * CVE-2014-7818
      &lt;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7818&gt;
    * CVE-2014-7829
      &lt;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7829&gt;

</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">slestso13-susestudio-1310-201502</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20150863-1/</URL>
      <Description>Link for SUSE-SU-2015:0863-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://lists.suse.com/pipermail/sle-security-updates/2015-May/001377.html</URL>
      <Description>E-Mail link for SUSE-SU-2015:0863-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/852794</URL>
      <Description>SUSE Bug 852794</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/876313</URL>
      <Description>SUSE Bug 876313</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/880078</URL>
      <Description>SUSE Bug 880078</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/887893</URL>
      <Description>SUSE Bug 887893</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/904372</URL>
      <Description>SUSE Bug 904372</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/904375</URL>
      <Description>SUSE Bug 904375</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/912512</URL>
      <Description>SUSE Bug 912512</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/914765</URL>
      <Description>SUSE Bug 914765</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/918203</URL>
      <Description>SUSE Bug 918203</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/918239</URL>
      <Description>SUSE Bug 918239</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/918395</URL>
      <Description>SUSE Bug 918395</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/919037</URL>
      <Description>SUSE Bug 919037</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-7818/</URL>
      <Description>SUSE CVE CVE-2014-7818 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-7819/</URL>
      <Description>SUSE CVE CVE-2014-7819 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-7829/</URL>
      <Description>SUSE CVE CVE-2014-7829 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="SUSE Studio Onsite 1.3">
      <Branch Type="Product Name" Name="SUSE Studio Onsite 1.3">
        <FullProductName ProductID="SUSE Studio Onsite 1.3" CPE="cpe:/o:suse:sle-studioonsite:1.3">SUSE Studio Onsite 1.3</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="Containment-Studio-SLE11_SP3-5.05.81-20150505234825">
      <FullProductName ProductID="Containment-Studio-SLE11_SP3-5.05.81-20150505234825">Containment-Studio-SLE11_SP3-5.05.81-20150505234825</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="susestudio-1.3.10-0.17.45">
      <FullProductName ProductID="susestudio-1.3.10-0.17.45">susestudio-1.3.10-0.17.45</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="susestudio-bundled-packages-1.3.10-0.17.45">
      <FullProductName ProductID="susestudio-bundled-packages-1.3.10-0.17.45">susestudio-bundled-packages-1.3.10-0.17.45</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="susestudio-common-1.3.10-0.17.45">
      <FullProductName ProductID="susestudio-common-1.3.10-0.17.45">susestudio-common-1.3.10-0.17.45</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="susestudio-runner-1.3.10-0.17.45">
      <FullProductName ProductID="susestudio-runner-1.3.10-0.17.45">susestudio-runner-1.3.10-0.17.45</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="susestudio-sid-1.3.10-0.17.45">
      <FullProductName ProductID="susestudio-sid-1.3.10-0.17.45">susestudio-sid-1.3.10-0.17.45</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="susestudio-ui-server-1.3.10-0.17.45">
      <FullProductName ProductID="susestudio-ui-server-1.3.10-0.17.45">susestudio-ui-server-1.3.10-0.17.45</FullProductName>
    </Branch>
    <Relationship ProductReference="Containment-Studio-SLE11_SP3-5.05.81-20150505234825" RelationType="Default Component Of" RelatesToProductReference="SUSE Studio Onsite 1.3">
      <FullProductName ProductID="SUSE Studio Onsite 1.3:Containment-Studio-SLE11_SP3-5.05.81-20150505234825">Containment-Studio-SLE11_SP3-5.05.81-20150505234825 as a component of SUSE Studio Onsite 1.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="susestudio-1.3.10-0.17.45" RelationType="Default Component Of" RelatesToProductReference="SUSE Studio Onsite 1.3">
      <FullProductName ProductID="SUSE Studio Onsite 1.3:susestudio-1.3.10-0.17.45">susestudio-1.3.10-0.17.45 as a component of SUSE Studio Onsite 1.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="susestudio-bundled-packages-1.3.10-0.17.45" RelationType="Default Component Of" RelatesToProductReference="SUSE Studio Onsite 1.3">
      <FullProductName ProductID="SUSE Studio Onsite 1.3:susestudio-bundled-packages-1.3.10-0.17.45">susestudio-bundled-packages-1.3.10-0.17.45 as a component of SUSE Studio Onsite 1.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="susestudio-common-1.3.10-0.17.45" RelationType="Default Component Of" RelatesToProductReference="SUSE Studio Onsite 1.3">
      <FullProductName ProductID="SUSE Studio Onsite 1.3:susestudio-common-1.3.10-0.17.45">susestudio-common-1.3.10-0.17.45 as a component of SUSE Studio Onsite 1.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="susestudio-runner-1.3.10-0.17.45" RelationType="Default Component Of" RelatesToProductReference="SUSE Studio Onsite 1.3">
      <FullProductName ProductID="SUSE Studio Onsite 1.3:susestudio-runner-1.3.10-0.17.45">susestudio-runner-1.3.10-0.17.45 as a component of SUSE Studio Onsite 1.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="susestudio-sid-1.3.10-0.17.45" RelationType="Default Component Of" RelatesToProductReference="SUSE Studio Onsite 1.3">
      <FullProductName ProductID="SUSE Studio Onsite 1.3:susestudio-sid-1.3.10-0.17.45">susestudio-sid-1.3.10-0.17.45 as a component of SUSE Studio Onsite 1.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="susestudio-ui-server-1.3.10-0.17.45" RelationType="Default Component Of" RelatesToProductReference="SUSE Studio Onsite 1.3">
      <FullProductName ProductID="SUSE Studio Onsite 1.3:susestudio-ui-server-1.3.10-0.17.45">susestudio-ui-server-1.3.10-0.17.45 as a component of SUSE Studio Onsite 1.3</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Directory traversal vulnerability in actionpack/lib/action_dispatch/middleware/static.rb in Action Pack in Ruby on Rails 3.x before 3.2.20, 4.0.x before 4.0.11, 4.1.x before 4.1.7, and 4.2.x before 4.2.0.beta3, when serve_static_assets is enabled, allows remote attackers to determine the existence of files outside the application root via a /..%2F sequence.</Note>
    </Notes>
    <CVE>CVE-2014-7818</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Studio Onsite 1.3:Containment-Studio-SLE11_SP3-5.05.81-20150505234825</ProductID>
        <ProductID>SUSE Studio Onsite 1.3:susestudio-1.3.10-0.17.45</ProductID>
        <ProductID>SUSE Studio Onsite 1.3:susestudio-bundled-packages-1.3.10-0.17.45</ProductID>
        <ProductID>SUSE Studio Onsite 1.3:susestudio-common-1.3.10-0.17.45</ProductID>
        <ProductID>SUSE Studio Onsite 1.3:susestudio-runner-1.3.10-0.17.45</ProductID>
        <ProductID>SUSE Studio Onsite 1.3:susestudio-sid-1.3.10-0.17.45</ProductID>
        <ProductID>SUSE Studio Onsite 1.3:susestudio-ui-server-1.3.10-0.17.45</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20150863-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-7818.html</URL>
        <Description>CVE-2014-7818</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/903662</URL>
        <Description>SUSE Bug 903662</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/905727</URL>
        <Description>SUSE Bug 905727</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Multiple directory traversal vulnerabilities in server.rb in Sprockets before 2.0.5, 2.1.x before 2.1.4, 2.2.x before 2.2.3, 2.3.x before 2.3.3, 2.4.x before 2.4.6, 2.5.x before 2.5.1, 2.6.x and 2.7.x before 2.7.1, 2.8.x before 2.8.3, 2.9.x before 2.9.4, 2.10.x before 2.10.2, 2.11.x before 2.11.3, 2.12.x before 2.12.3, and 3.x before 3.0.0.beta.3, as distributed with Ruby on Rails 3.x and 4.x, allow remote attackers to determine the existence of files outside the application root via a ../ (dot dot slash) sequence with (1) double slashes or (2) URL encoding.</Note>
    </Notes>
    <CVE>CVE-2014-7819</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Studio Onsite 1.3:Containment-Studio-SLE11_SP3-5.05.81-20150505234825</ProductID>
        <ProductID>SUSE Studio Onsite 1.3:susestudio-1.3.10-0.17.45</ProductID>
        <ProductID>SUSE Studio Onsite 1.3:susestudio-bundled-packages-1.3.10-0.17.45</ProductID>
        <ProductID>SUSE Studio Onsite 1.3:susestudio-common-1.3.10-0.17.45</ProductID>
        <ProductID>SUSE Studio Onsite 1.3:susestudio-runner-1.3.10-0.17.45</ProductID>
        <ProductID>SUSE Studio Onsite 1.3:susestudio-sid-1.3.10-0.17.45</ProductID>
        <ProductID>SUSE Studio Onsite 1.3:susestudio-ui-server-1.3.10-0.17.45</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>low</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20150863-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-7819.html</URL>
        <Description>CVE-2014-7819</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/903658</URL>
        <Description>SUSE Bug 903658</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="3">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Directory traversal vulnerability in actionpack/lib/action_dispatch/middleware/static.rb in Action Pack in Ruby on Rails 3.x before 3.2.21, 4.0.x before 4.0.12, 4.1.x before 4.1.8, and 4.2.x before 4.2.0.beta4, when serve_static_assets is enabled, allows remote attackers to determine the existence of files outside the application root via vectors involving a \ (backslash) character, a similar issue to CVE-2014-7818.</Note>
    </Notes>
    <CVE>CVE-2014-7829</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Studio Onsite 1.3:Containment-Studio-SLE11_SP3-5.05.81-20150505234825</ProductID>
        <ProductID>SUSE Studio Onsite 1.3:susestudio-1.3.10-0.17.45</ProductID>
        <ProductID>SUSE Studio Onsite 1.3:susestudio-bundled-packages-1.3.10-0.17.45</ProductID>
        <ProductID>SUSE Studio Onsite 1.3:susestudio-common-1.3.10-0.17.45</ProductID>
        <ProductID>SUSE Studio Onsite 1.3:susestudio-runner-1.3.10-0.17.45</ProductID>
        <ProductID>SUSE Studio Onsite 1.3:susestudio-sid-1.3.10-0.17.45</ProductID>
        <ProductID>SUSE Studio Onsite 1.3:susestudio-ui-server-1.3.10-0.17.45</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20150863-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-7829.html</URL>
        <Description>CVE-2014-7829</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/905727</URL>
        <Description>SUSE Bug 905727</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
