CVE-2017-9731: Infoleak
Published Jun 16, 2017
·Updated
In meta/classes/packageipk.bbclass in Poky in poky-pyro 17.0.0 for Yocto Project through YP Core - Pyro 2.3, attackers can obtain sensitive information by reading a URL in a Source entry in an ipk package.
Affected Software
1 affected component
Yocto Project Yp Core-pyro=2.3
Remediation
Event History
Jun 16, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-9731?
CVE-2017-9731 is considered to have a low severity, allowing attackers to obtain sensitive information.
2
How do I fix CVE-2017-9731?
To fix CVE-2017-9731, upgrade to a version of the Yocto Project that addresses this vulnerability.
3
What affected software versions are associated with CVE-2017-9731?
CVE-2017-9731 affects Yocto Project version 2.3 specifically.
4
What type of information can be exposed by CVE-2017-9731?
CVE-2017-9731 allows attackers to read sensitive information contained in a URL in a Source entry of an ipk package.
5
Is there a direct link to the patch for CVE-2017-9731?
Yes, the direct link to the patch for CVE-2017-9731 is available in the Yocto Project repository.