CVE-2017-14804P4CRITICALCVSS 9.9fixed in obs-build 20180302-1 (bookworm)2017
CVE-2017-14804 [CRITICAL] CVE-2017-14804: obs-build - The build package before 20171128 did not check directory names during extractio...
The build package before 20171128 did not check directory names during extraction of build results that allowed untrusted builds to write outside of the target system,allowing escape out of buildroots.
Scope: local
bookworm: resolved (fixed in 20180302-1)
bullseye: resolved (fixed in 20180302-1)
forky: resolved (fixed in 20180302-1)
sid: resolved (fixed in 201
debian