cbcvebase.
CVE-2017-14804
published 2018-03-01

CVE-2017-14804: The build package before 20171128 did not check directory names during extraction of build results that allowed untrusted builds to write outside of the target…

medium5.3CVSS 3.0
AVNACLPRNUINSUCNILAN
The build package before 20171128 did not check directory names during extraction of build results that allowed untrusted builds to write outside of the target system,allowing escape out of buildroots.

Affected

6 ranges
VendorProductVersion rangeFixed in
debianobs-build< obs-build 20180302-1 (bookworm)obs-build 20180302-1 (bookworm)
opensuseleap
opensuseleap
susebuildunspecified – 20171128
suselinux_enterprise_software_development_kit
suselinux_enterprise_software_development_kit

CVSS provenance

nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
osv5.3MEDIUM