The build package before 20171128 did not check directory names during extraction of build results that allowed untrusted builds to write outside of the target system,allowing escape out of buildroots.
CVSS Details
- CVSS 3.1 Base Score: 9.9
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade obs-build | Jul 30, 2024 | Mar 1, 2018 |
| Suse | — | Upgrade build-mkdrpmsUpgrade oscUpgrade buildUpgrade build-mkbaselibsUpgrade build-initvm-i586Upgrade obs-service-source_validatorUpgrade build-initvm-x86_64Upgrade build-initvm-s390 | Dec 8, 2017 | Dec 8, 2017 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Mar 1, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub