A directory traversal issue was found in reposync, a part of yum-utils, where reposync fails to sanitize paths in remote repository configuration files. If an attacker controls a repository, they may be able to copy files outside of the destination directory on the targeted system via path traversal. If reposync is running with heightened privileges on a targeted system, this flaw could potentially result in system compromise via the overwriting of critical system files. Version 1.1.31 and older are believed to be affected.
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Link | Tags |
---|---|
http://www.securitytracker.com/id/1041594 | third party advisory vdb entry |
https://access.redhat.com/errata/RHSA-2018:2285 | third party advisory vendor advisory |
https://access.redhat.com/errata/RHSA-2018:2284 | third party advisory vendor advisory |
https://github.com/rpm-software-management/yum-utils/commit/6a8de061f8fdc885e74ebe8c94625bf53643b71c | third party advisory patch |
https://access.redhat.com/errata/RHSA-2018:2626 | third party advisory vendor advisory |
https://github.com/rpm-software-management/yum-utils/commit/7554c0133eb830a71dc01846037cc047d0acbc2c | third party advisory patch |
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10897 | patch third party advisory issue tracking |
https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0 | third party advisory |
https://github.com/rpm-software-management/yum-utils/pull/43 | third party advisory |