PT-2018-9573 · Alpine · Alpine Linux+1

Max Justicz

·

Published

2018-12-20

·

Updated

2020-03-18

·

CVE-2018-1000849

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Alpine Linux versions prior to 2.6.10 Alpine Linux versions prior to 2.7.6 Alpine Linux versions prior to 2.10.1
Description The issue is related to a bug in apk-tools, Alpine Linux' package manager, which can result in Remote Code Execution. A specially crafted APK-file can cause apk to write arbitrary data to an attacker-specified file due to bugs in handling long link target name and the way a regular file is extracted.
Recommendations For versions prior to 2.6.10, update to version 2.6.10 or later. For versions prior to 2.7.6, update to version 2.7.6 or later. For versions prior to 2.10.1, update to version 2.10.1 or later.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-1000849

Affected Products

Alpine Linux
Apk-Tools