In meta/classes/package_ipk.bbclass in Poky in poky-pyro 17.0.0 for Yocto Project through YP Core - Pyro 2.3, attackers can obtain sensitive information by reading a URL in a Source entry in an ipk package.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2017-06-16T15:00:00

Updated: 2017-06-16T15:57:01

Reserved: 2017-06-16T00:00:00


Link: CVE-2017-9731

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2017-06-16T15:29:00.910

Modified: 2017-07-05T16:22:11.477


Link: CVE-2017-9731

JSON object: View

cve-icon Redhat Information

No data.

CWE