The build package before 20171128 did not check directory names during extraction of build results that allowed untrusted builds to write outside of the target system,allowing escape out of buildroots.
CVSS Details
- CVSS 3.1 Base Score: 9.9
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade obs-build | Jul 30, 2024 | Mar 1, 2018 |
| Suse | — | Upgrade build-mkdrpmsUpgrade build-mkbaselibsUpgrade oscUpgrade buildUpgrade build-initvm-x86_64Upgrade build-initvm-s390Upgrade build-initvm-i586Upgrade obs-service-source_validator | Dec 8, 2017 | Dec 8, 2017 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Mar 1, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub