The build package before 20171128 did not check directory names during extraction of build results that allowed untrusted builds to write outside of the target system,allowing escape out of buildroots.
CVSS Details
- CVSS 3.1 Base Score: 9.9
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade obs-build | Jul 30, 2024 | Mar 1, 2018 |
| Suse | — | Upgrade oscUpgrade build-mkbaselibsUpgrade build-mkdrpmsUpgrade buildUpgrade build-initvm-s390Upgrade obs-service-source_validatorUpgrade build-initvm-i586Upgrade build-initvm-x86_64 | Dec 8, 2017 | Dec 8, 2017 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Mar 1, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub