VulnerabilityModified
CVE-2017-14804
The build package before 20171128 did not check directory names during extraction of build results that allowed untrusted builds to write outside of the target system,allowing escape out of buildroots.
MEDIUM 5.3EPSS 1.71%
Does this matter?
Lower severity and a low EPSS score (1.71%). Track it; it rarely justifies an emergency change on its own.
Description
The build package before 20171128 did not check directory names during extraction of build results that allowed untrusted builds to write outside of the target system,allowing escape out of buildroots.
- CVSS 3.0
- 5.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 1.71% probability · 76th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22, CWE-20
- Affected
- suse/linux enterprise software development kit · opensuse/leap
- Source
- security@opentext.com
References
- https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00024.html
- https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00025.html
- https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00030.html
- https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00024.html
- https://lists.opensuse.org/opensuse-security-announce/2017-12/msg00025.html
- https://lists.opensuse.org/opensuse-security-announce/2018-01/msg00030.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.