The build package before 20171128 did not check directory names during extraction of build results that allowed untrusted builds to write outside of the target system,allowing escape out of buildroots.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: microfocus

Published: 2018-03-01T19:00:00Z

Updated: 2024-09-16T22:03:14.200Z

Reserved: 2017-09-27T00:00:00

Link: CVE-2017-14804

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-03-01T20:29:00.413

Modified: 2024-11-21T03:13:32.357

Link: CVE-2017-14804

cve-icon Redhat

No data.