CVE-2017-14804: Opensuse Leap

Medium severity, CVSS 5.3. EPSS: 1.7% chance of exploitation in the next 30 days.

The build package before 20171128 did not check directory names during extraction of build results that allowed untrusted builds to write outside of the target system,allowing escape out of buildroots.

Affected products

  • Opensuse Leap: version 42.2 only; version 42.3 only
  • Suse Linux Enterprise Software Development Kit: version 11 only; version 12 only

Published 2018-03-01. Last modified 2026-06-17.