CVE-2017-14804: package builds could use directory traversal to write outside of target area
The build package before 20171128 did not check directory names during extraction of build results that allowed untrusted builds to write outside of the target system,allowing escape out of buildroots.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-14804?
CVE-2017-14804 is a vulnerability that allows untrusted builds to write outside of the target system, potentially leading to an escape out of buildroots.
Which software versions are affected by CVE-2017-14804?
CVE-2017-14804 affects SUSE Linux Enterprise Software Development Kit 11 SP4, SUSE Linux Enterprise Software Development Kit 12 SP2, SUSE Linux Enterprise Software Development Kit 12 SP3, openSUSE Leap 42.2, and openSUSE Leap 42.3.
How severe is CVE-2017-14804?
CVE-2017-14804 has a severity rating of 5.3 out of 10, making it a critical vulnerability.
How can I fix CVE-2017-14804?
To fix CVE-2017-14804, update to the latest version of the build package (20171128 or later) that includes the fix for checking directory names during extraction of build results.
Where can I find more information about CVE-2017-14804?
You can find more information about CVE-2017-14804 at the following references: [1] [2] [3].