CVE-2018-10897
published 2018-08-01CVE-2018-10897: A directory traversal issue was found in reposync, a part of yum-utils, where reposync fails to sanitize paths in remote repository configuration files. If an…
PriorityP349high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
5.71%
92.2th percentile
A directory traversal issue was found in reposync, a part of yum-utils, where reposync fails to sanitize paths in remote repository configuration files. If an attacker controls a repository, they may be able to copy files outside of the destination directory on the targeted system via path traversal. If reposync is running with heightened privileges on a targeted system, this flaw could potentially result in system compromise via the overwriting of critical system files. Version 1.1.31 and older are believed to be affected.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | virtualization | — | — |
| rpm | yum-utils | <= 1.1.31 | — |
| the_rpm_project | yum-utils | — | — |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
yum-utils: reposync: improper path validation may lead to directory traversal
vendor_redhat·2018-07-11·CVSS 8.1
CVE-2018-10897 [HIGH] CWE-22 yum-utils: reposync: improper path validation may lead to directory traversal
yum-utils: reposync: improper path validation may lead to directory traversal
A directory traversal issue was found in reposync, a part of yum-utils, where reposync fails to sanitize paths in remote repository configuration files. If an attacker controls a repository, they may be able to copy files outside of the destination directory on the targeted system via path traversal. If reposync is running with heightened privileges on a targeted system, this flaw could potentially result in system compromise via the overwriting of critical system files. Version 1.1.31 and older are believed to be affected.
A directory traversal issue was found in reposync, a part of yum-utils, where reposync fails to sanitize paths in remote repository configuration files. If an attacker controls a repository,
GHSA
GHSA-48q2-62w2-89cw: A directory traversal issue was found in reposync, a part of yum-utils, where reposync fails to sanitize paths in remote repository configuration file
ghsa_unreviewed·2022-05-13
CVE-2018-10897 [HIGH] CWE-22 GHSA-48q2-62w2-89cw: A directory traversal issue was found in reposync, a part of yum-utils, where reposync fails to sanitize paths in remote repository configuration file
A directory traversal issue was found in reposync, a part of yum-utils, where reposync fails to sanitize paths in remote repository configuration files. If an attacker controls a repository, they may be able to copy files outside of the destination directory on the targeted system via path traversal. If reposync is running with heightened privileges on a targeted system, this flaw could potentially result in system compromise via the overwriting of critical system files. Version 1.1.31 and older are believed to be affected.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-10897 dnf-plugins-core: yum-utils: reposync: improper path validation may lead to directory traversal [fedora-all]
bugzilla·2018-07-27·CVSS 8.1
CVE-2018-10897 [HIGH] CVE-2018-10897 dnf-plugins-core: yum-utils: reposync: improper path validation may lead to directory traversal [fedora-all]
CVE-2018-10897 dnf-plugins-core: yum-utils: reposync: improper path validation may lead to directory traversal [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE:
Bugzilla
CVE-2018-10897 yum-utils: reposync: improper path validation may lead to directory traversal [fedora-all]
bugzilla·2018-07-12·CVSS 8.1
CVE-2018-10897 [HIGH] CVE-2018-10897 yum-utils: reposync: improper path validation may lead to directory traversal [fedora-all]
CVE-2018-10897 yum-utils: reposync: improper path validation may lead to directory traversal [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects
Bugzilla
CVE-2018-10897 yum-utils: reposync: improper path validation may lead to directory traversal
bugzilla·2018-07-11·CVSS 8.1
CVE-2018-10897 [HIGH] CVE-2018-10897 yum-utils: reposync: improper path validation may lead to directory traversal
CVE-2018-10897 yum-utils: reposync: improper path validation may lead to directory traversal
Reposync fails to sanitize paths in remote repository configuration files. If an attacker controls a repository a user is syncing with, the attacker may be able to copy files outside of the destination directory via path traversal. If reposync is running with heightened privileges on a targeted system, this flaw could potentially result in system compromise via the overwriting of critical system files.
Discussion:
Created yum-utils tracking bugs for this issue:
Affects: fedora-all [bug 1600454]
---
Acknowledgments:
Name: Jay Grizzard (Clover Network), Aaron Levy (Clover Network)
---
Statement:
Red Hat Enterprise Virtualization includes reposync as a component from the base Enterprise Linu
http://www.securitytracker.com/id/1041594https://access.redhat.com/errata/RHSA-2018:2284https://access.redhat.com/errata/RHSA-2018:2285https://access.redhat.com/errata/RHSA-2018:2626https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10897https://github.com/rpm-software-management/yum-utils/commit/6a8de061f8fdc885e74ebe8c94625bf53643b71chttps://github.com/rpm-software-management/yum-utils/commit/7554c0133eb830a71dc01846037cc047d0acbc2chttps://github.com/rpm-software-management/yum-utils/pull/43https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0http://www.securitytracker.com/id/1041594https://access.redhat.com/errata/RHSA-2018:2284https://access.redhat.com/errata/RHSA-2018:2285https://access.redhat.com/errata/RHSA-2018:2626https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10897https://github.com/rpm-software-management/yum-utils/commit/6a8de061f8fdc885e74ebe8c94625bf53643b71chttps://github.com/rpm-software-management/yum-utils/commit/7554c0133eb830a71dc01846037cc047d0acbc2chttps://github.com/rpm-software-management/yum-utils/pull/43https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0
2018-08-01
Published