ZeroHour

CVE-2017-14804

CVSS 3.0
5.3 medium
EPSS
2%p76
Published
()
Modified
Description

The build package before 20171128 did not check directory names during extraction of build results that allowed untrusted builds to write outside of the target system,allowing escape out of buildroots.

Vendors
suseopensuse
Products
linux enterprise software development kit, leap
Weakness
CWE-22, CWE-20
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.