A vulnerability was found in the build script of obs-build. It is possible to exploit the extractbuild script to write to files in the host system, in case of a vm build. This can be used, for instance, to replace a running bs_worker with arbitrary code. Suse bug report (contains reproducer): https://bugzilla.novell.com/show_bug.cgi?id=1069904
Created obs-build tracking bugs for this issue: Affects: fedora-all [bug 1535058]
This had been fixed in https://bodhi.fedoraproject.org/updates/FEDORA-2018-ac8aab1f7a
Oops, not fixed.
Fixed in: https://bodhi.fedoraproject.org/updates/FEDORA-2018-fe2cbf0c2b