PT-2019-15691 · Crun Team+1 · Crun+1
Published
2019-11-13
·
Updated
2019-12-13
·
CVE-2019-18837
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
crun versions prior to 0.10.5
Description
An issue was discovered in crun where it doesn't correctly check whether a target is a symlink when a crafted image is used, resulting in access to files outside of the container. This issue is related to the
libcrun/linux.c and libcrun/chroot realpath.c files.Recommendations
For versions prior to 0.10.5, update to version 0.10.5 or later to resolve the issue. As a temporary workaround, consider restricting access to crafted images to minimize the risk of exploitation.
Fix
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Crun