Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package yast2-auth-client for openSUSE:Factory checked in at 2026-09-30 16:21:51 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/yast2-auth-client (Old) and /work/SRC/openSUSE:Factory/.yast2-auth-client.new.1465845 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "yast2-auth-client" Wed Sep 30 16:21:51 2026 rev:55 rq:1381515 version:5.0.5 Changes: -------- --- /work/SRC/openSUSE:Factory/yast2-auth-client/yast2-auth-client.changes 2026-03-27 06:53:03.810771681 +0100 +++ /work/SRC/openSUSE:Factory/.yast2-auth-client.new.1465845/yast2-auth-client.changes 2026-09-30 16:22:38.967340010 +0200 @@ -1,0 +2,11 @@ +Wed Aug 12 12:31:12 UTC 2026 - Noel Power <[email protected]> + +- fix non specified optional params being unconditionally added to + net cmd arg list; (bsc#1274806). +- fix undefined conf.ad_user (NameError) in netcmd call; + (bsc#1274612). +- CVE-2026-59681: yast2-auth-client: OS command injection via + unsanitized passed to net cmd. +- Bump version to 5.0.5 for bsc#1272775. + +------------------------------------------------------------------- Old: ---- yast2-auth-client-5.0.4.tar.bz2 New: ---- yast2-auth-client-5.0.5.tar.bz2 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ yast2-auth-client.spec ++++++ --- /var/tmp/diff_new_pack.Ug4378/_old 2026-09-30 16:22:39.654368740 +0200 +++ /var/tmp/diff_new_pack.Ug4378/_new 2026-09-30 16:22:39.655368782 +0200 @@ -17,7 +17,7 @@ Name: yast2-auth-client -Version: 5.0.4 +Version: 5.0.5 Release: 0 URL: https://github.com/yast/yast-auth-client Summary: YaST2 - Centralised System Authentication Configuration ++++++ yast2-auth-client-5.0.4.tar.bz2 -> yast2-auth-client-5.0.5.tar.bz2 ++++++ diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/yast2-auth-client-5.0.4/package/yast2-auth-client.changes new/yast2-auth-client-5.0.5/package/yast2-auth-client.changes --- old/yast2-auth-client-5.0.4/package/yast2-auth-client.changes 2026-03-25 18:29:57.000000000 +0100 +++ new/yast2-auth-client-5.0.5/package/yast2-auth-client.changes 2026-09-29 18:30:18.000000000 +0200 @@ -1,4 +1,15 @@ ------------------------------------------------------------------- +Wed Aug 12 12:31:12 UTC 2026 - Noel Power <[email protected]> + +- fix non specified optional params being unconditionally added to + net cmd arg list; (bsc#1274806). +- fix undefined conf.ad_user (NameError) in netcmd call; + (bsc#1274612). +- CVE-2026-59681: yast2-auth-client: OS command injection via + unsanitized passed to net cmd. +- Bump version to 5.0.5 for bsc#1272775. + +------------------------------------------------------------------- Tue Mar 10 09:00:28 UTC 2026 - Michal Filka <[email protected]> - jsc#PED-14507 diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/yast2-auth-client-5.0.4/package/yast2-auth-client.spec new/yast2-auth-client-5.0.5/package/yast2-auth-client.spec --- old/yast2-auth-client-5.0.4/package/yast2-auth-client.spec 2026-03-25 18:29:57.000000000 +0100 +++ new/yast2-auth-client-5.0.5/package/yast2-auth-client.spec 2026-09-29 18:30:18.000000000 +0200 @@ -17,7 +17,7 @@ Name: yast2-auth-client -Version: 5.0.4 +Version: 5.0.5 Release: 0 Url: https://github.com/yast/yast-auth-client Summary: YaST2 - Centralised System Authentication Configuration diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/yast2-auth-client-5.0.4/src/lib/auth/authconf.rb new/yast2-auth-client-5.0.5/src/lib/auth/authconf.rb --- old/yast2-auth-client-5.0.4/src/lib/auth/authconf.rb 2026-03-25 18:29:57.000000000 +0100 +++ new/yast2-auth-client-5.0.5/src/lib/auth/authconf.rb 2026-09-29 18:30:18.000000000 +0200 @@ -830,7 +830,8 @@ if !ad_install_samba return '' end - out, status = Open3.capture2("net ads lookup -S #{ad_host_or_domain}") + netcmd = ["net", "ads", "lookup", "-S", "#{ad_host_or_domain}"] + out, status = Open3.capture2(*netcmd) if status.exitstatus != 0 return '' end @@ -854,7 +855,8 @@ if smb_conf.nil? return [false, false] end - _, status = Open3.capture2("net -s #{smb_conf.path} ads testjoin") + netcmd = ["net","-s", "#{smb_conf.path}", "ads", "testjoin"] + _, status = Open3.capture2(*netcmd) ad_has_computer = status.exitstatus == 0 klist, _ = Open3.capture2("klist -k") kerberos_has_key = klist.split("\n").any?{ |line| /#{Socket.gethostname}.*#{ad_domain_name.downcase}/.match(line.downcase) } @@ -918,11 +920,21 @@ exitstatus = 0 ou_param = @ad_ou.to_s == '' ? '' : "createcomputer=#{@ad_ou}" dnshostname_param = @ad_dnshostname.to_s == '' ? '' : "dnshostname=#{@ad_dnshostname}" - netcmd = "net -s #{smb_conf.path} ads join #{ou_param} #{dnshostname_param} -U #{@ad_user}" + netcmd = [ + "net", + "-s", + "#{smb_conf.path}", + "ads", + "join", + ] + netcmd << "#{ou_param}" unless ou_param.empty? + netcmd << "#{dnshostname_param}" unless dnshostname_param.empty? + netcmd += ["-U", "#{@ad_user}"] + if !@ad_update_dns - netcmd += ' --no-dns-updates' + netcmd << '--no-dns-updates' end - Open3.popen2(netcmd){ |stdin, stdout, control| + Open3.popen2(*netcmd){ |stdin, stdout, control| stdin.print(@ad_pass + "\n") stdin.close output = stdout.read
