Unrated severityNVD Advisory· Published Mar 1, 2018· Updated Sep 16, 2024
package builds could use directory traversal to write outside of target area
CVE-2017-14804
Description
The build package before 20171128 did not check directory names during extraction of build results that allowed untrusted builds to write outside of the target system,allowing escape out of buildroots.
Affected products
12- osv-coords10 versionspkg:rpm/opensuse/build&distro=openSUSE%20Leap%2015.0pkg:rpm/suse/build&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015pkg:rpm/suse/build&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP4pkg:rpm/suse/build&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP2pkg:rpm/suse/build&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP3pkg:rpm/suse/obs-service-source_validator&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP2pkg:rpm/suse/obs-service-source_validator&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP3pkg:rpm/suse/osc&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP4pkg:rpm/suse/osc&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP2pkg:rpm/suse/osc&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP3
< 20190128-lp150.2.3.1+ 9 more
- (no CPE)range: < 20190128-lp150.2.3.1
- (no CPE)range: < 20190128-3.3.2
- (no CPE)range: < 20171128-8.3.3
- (no CPE)range: < 20171128-9.3.2
- (no CPE)range: < 20171128-9.3.2
- (no CPE)range: < 0.7-9.3.1
- (no CPE)range: < 0.7-9.3.1
- (no CPE)range: < 0.162.1-7.4.1
- (no CPE)range: < 0.162.0-15.3.1
- (no CPE)range: < 0.162.0-15.3.1
- SUSE/buildv5Range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- lists.opensuse.org/opensuse-security-announce/2017-12/msg00024.htmlmitrevendor-advisoryx_refsource_SUSE
- lists.opensuse.org/opensuse-security-announce/2017-12/msg00025.htmlmitrevendor-advisoryx_refsource_SUSE
- lists.opensuse.org/opensuse-security-announce/2018-01/msg00030.htmlmitrevendor-advisoryx_refsource_SUSE
News mentions
0No linked articles in our index yet.