The build package before 20171128 did not check directory names during extraction of build results that allowed untrusted builds to write outside of the target system,allowing escape out of buildroots.
CVSS Details
- CVSS 3.1 Base Score: 9.9
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade obs-build | Jul 30, 2024 | Mar 1, 2018 |
| Suse | — | Upgrade build-initvm-i586Upgrade build-initvm-x86_64Upgrade build-initvm-s390Upgrade obs-service-source_validatorUpgrade build-mkdrpmsUpgrade buildUpgrade oscUpgrade build-mkbaselibs | Dec 8, 2017 | Dec 8, 2017 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Mar 1, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub