Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package yast2-auth-client for 
openSUSE:Factory checked in at 2026-09-30 16:21:51
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/yast2-auth-client (Old)
 and      /work/SRC/openSUSE:Factory/.yast2-auth-client.new.1465845 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "yast2-auth-client"

Wed Sep 30 16:21:51 2026 rev:55 rq:1381515 version:5.0.5

Changes:
--------
--- /work/SRC/openSUSE:Factory/yast2-auth-client/yast2-auth-client.changes      
2026-03-27 06:53:03.810771681 +0100
+++ 
/work/SRC/openSUSE:Factory/.yast2-auth-client.new.1465845/yast2-auth-client.changes
 2026-09-30 16:22:38.967340010 +0200
@@ -1,0 +2,11 @@
+Wed Aug 12 12:31:12 UTC 2026 - Noel Power <[email protected]>
+
+- fix non specified optional params being unconditionally added to
+  net cmd arg list; (bsc#1274806).
+- fix undefined conf.ad_user (NameError) in netcmd call;
+  (bsc#1274612).
+- CVE-2026-59681: yast2-auth-client: OS command injection via
+  unsanitized passed to net cmd.
+- Bump version to 5.0.5 for bsc#1272775.
+
+-------------------------------------------------------------------

Old:
----
  yast2-auth-client-5.0.4.tar.bz2

New:
----
  yast2-auth-client-5.0.5.tar.bz2

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ yast2-auth-client.spec ++++++
--- /var/tmp/diff_new_pack.Ug4378/_old  2026-09-30 16:22:39.654368740 +0200
+++ /var/tmp/diff_new_pack.Ug4378/_new  2026-09-30 16:22:39.655368782 +0200
@@ -17,7 +17,7 @@
 
 
 Name:           yast2-auth-client
-Version:        5.0.4
+Version:        5.0.5
 Release:        0
 URL:            https://github.com/yast/yast-auth-client
 Summary:        YaST2 - Centralised System Authentication Configuration

++++++ yast2-auth-client-5.0.4.tar.bz2 -> yast2-auth-client-5.0.5.tar.bz2 ++++++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/yast2-auth-client-5.0.4/package/yast2-auth-client.changes 
new/yast2-auth-client-5.0.5/package/yast2-auth-client.changes
--- old/yast2-auth-client-5.0.4/package/yast2-auth-client.changes       
2026-03-25 18:29:57.000000000 +0100
+++ new/yast2-auth-client-5.0.5/package/yast2-auth-client.changes       
2026-09-29 18:30:18.000000000 +0200
@@ -1,4 +1,15 @@
 -------------------------------------------------------------------
+Wed Aug 12 12:31:12 UTC 2026 - Noel Power <[email protected]>
+
+- fix non specified optional params being unconditionally added to
+  net cmd arg list; (bsc#1274806).
+- fix undefined conf.ad_user (NameError) in netcmd call;
+  (bsc#1274612).
+- CVE-2026-59681: yast2-auth-client: OS command injection via
+  unsanitized passed to net cmd.
+- Bump version to 5.0.5 for bsc#1272775.
+
+-------------------------------------------------------------------
 Tue Mar 10 09:00:28 UTC 2026 - Michal Filka <[email protected]>
 
 - jsc#PED-14507
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/yast2-auth-client-5.0.4/package/yast2-auth-client.spec 
new/yast2-auth-client-5.0.5/package/yast2-auth-client.spec
--- old/yast2-auth-client-5.0.4/package/yast2-auth-client.spec  2026-03-25 
18:29:57.000000000 +0100
+++ new/yast2-auth-client-5.0.5/package/yast2-auth-client.spec  2026-09-29 
18:30:18.000000000 +0200
@@ -17,7 +17,7 @@
 
 
 Name:           yast2-auth-client
-Version:        5.0.4
+Version:        5.0.5
 Release:        0
 Url:            https://github.com/yast/yast-auth-client
 Summary:        YaST2 - Centralised System Authentication Configuration
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/yast2-auth-client-5.0.4/src/lib/auth/authconf.rb 
new/yast2-auth-client-5.0.5/src/lib/auth/authconf.rb
--- old/yast2-auth-client-5.0.4/src/lib/auth/authconf.rb        2026-03-25 
18:29:57.000000000 +0100
+++ new/yast2-auth-client-5.0.5/src/lib/auth/authconf.rb        2026-09-29 
18:30:18.000000000 +0200
@@ -830,7 +830,8 @@
             if !ad_install_samba
                 return ''
             end
-            out, status = Open3.capture2("net ads lookup -S 
#{ad_host_or_domain}")
+            netcmd = ["net", "ads", "lookup", "-S", "#{ad_host_or_domain}"]
+            out, status = Open3.capture2(*netcmd)
             if status.exitstatus != 0
                 return ''
             end
@@ -854,7 +855,8 @@
             if smb_conf.nil?
                 return [false, false]
             end
-            _, status = Open3.capture2("net -s #{smb_conf.path} ads testjoin")
+            netcmd = ["net","-s", "#{smb_conf.path}", "ads", "testjoin"]
+            _, status = Open3.capture2(*netcmd)
             ad_has_computer = status.exitstatus == 0
             klist, _ = Open3.capture2("klist -k")
             kerberos_has_key = klist.split("\n").any?{ |line| 
/#{Socket.gethostname}.*#{ad_domain_name.downcase}/.match(line.downcase) }
@@ -918,11 +920,21 @@
             exitstatus = 0
             ou_param = @ad_ou.to_s == '' ? '' : "createcomputer=#{@ad_ou}"
             dnshostname_param = @ad_dnshostname.to_s == '' ? '' : 
"dnshostname=#{@ad_dnshostname}"
-            netcmd = "net -s #{smb_conf.path} ads join #{ou_param} 
#{dnshostname_param} -U #{@ad_user}"
+            netcmd = [
+              "net",
+              "-s",
+              "#{smb_conf.path}",
+              "ads",
+              "join",
+            ]
+            netcmd << "#{ou_param}" unless ou_param.empty?
+            netcmd << "#{dnshostname_param}" unless dnshostname_param.empty?
+            netcmd += ["-U", "#{@ad_user}"]
+
             if !@ad_update_dns
-                netcmd += ' --no-dns-updates'
+                netcmd << '--no-dns-updates'
             end
-            Open3.popen2(netcmd){ |stdin, stdout, control|
+            Open3.popen2(*netcmd){ |stdin, stdout, control|
                 stdin.print(@ad_pass + "\n")
                 stdin.close
                 output = stdout.read

Reply via email to