The build package before 20171128 did not check directory names during extraction of build results that allowed untrusted builds to write outside of the target system,allowing escape out of buildroots.
| Software | From | Fixed in |
|---|---|---|
| suse / linux_enterprise_software_development_kit | 12-sp2 | 12-sp2.x |
| suse / linux_enterprise_software_development_kit | 11-sp4 | 11-sp4.x |
| suse / linux_enterprise_software_development_kit | 12-sp3 | 12-sp3.x |
| opensuse / leap | 42.3 | 42.3.x |
| opensuse / leap | 42.2 | 42.2.x |