VYPR
Unrated severityNVD Advisory· Published Mar 1, 2018· Updated Sep 16, 2024

package builds could use directory traversal to write outside of target area

CVE-2017-14804

Description

The build package before 20171128 did not check directory names during extraction of build results that allowed untrusted builds to write outside of the target system,allowing escape out of buildroots.

Affected products

12

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.