PT-2018-2217 · Yum+2 · Yum-Utils+2

Dmnks

·

Published

2018-07-30

·

Updated

2023-02-13

·

CVE-2018-10897

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions yum-utils versions 1.1.31 and older
Description A directory traversal issue exists in reposync, a part of yum-utils, due to insufficient path sanitization in remote repository configuration files. This allows an attacker controlling a repository to potentially copy files outside the destination directory on a targeted system via path traversal. If reposync runs with heightened privileges, this flaw could result in system compromise by overwriting critical system files. The issue may enable a remote attacker to create, modify, or delete arbitrary files.
Recommendations For versions 1.1.31 and older, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Link Following

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-00254
CESA-2018_2284
CESA-2018_2285
CVE-2018-10897
RHSA-2018:2284
RHSA-2018:2285
RHSA-2018:2626
RHSA-2018_2284
RHSA-2018_2285

Affected Products

Centos
Red Hat
Yum-Utils