CVE-2019-18466
published 2019-10-28CVE-2019-18466: An issue was discovered in Podman in libpod before 1.6.0. It resolves a symlink in the host context during a copy operation from the container to the host…
PriorityP423medium5.5CVSS 3.1
AVLACLPRNUIRSUCNIHAN
EPSS
1.49%
71.2th percentile
An issue was discovered in Podman in libpod before 1.6.0. It resolves a symlink in the host context during a copy operation from the container to the host, because an undesired glob operation occurs. An attacker could create a container image containing particular symlinks that, when copied by a victim user to the host filesystem, may overwrite existing files with others from the host.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libpod | — | — |
| github.com | containers_libpod | >= 0 < 1.6.0 | 1.6.0 |
| github.com | containers_podman_v4 | >= 0 < 1.6.0 | 1.6.0 |
| libpod_project | libpod | < 1.6.0 | 1.6.0 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:P
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Podman Symlink Vulnerability in github.com/containers/libpod
osv·2024-08-20
CVE-2019-18466 Podman Symlink Vulnerability in github.com/containers/libpod
Podman Symlink Vulnerability in github.com/containers/libpod
Podman Symlink Vulnerability in github.com/containers/libpod
OSV
Podman Symlink Vulnerability
osv·2022-05-24
CVE-2019-18466 [MEDIUM] Podman Symlink Vulnerability
Podman Symlink Vulnerability
An issue was discovered in Podman in libpod before 1.6.0. It resolves a symlink in the host context during a copy operation from the container to the host, because an undesired glob operation occurs. An attacker could create a container image containing particular symlinks that, when copied by a victim user to the host filesystem, may overwrite existing files with others from the host.
GHSA
Podman Symlink Vulnerability
ghsa·2022-05-24
CVE-2019-18466 [MEDIUM] CWE-59 Podman Symlink Vulnerability
Podman Symlink Vulnerability
An issue was discovered in Podman in libpod before 1.6.0. It resolves a symlink in the host context during a copy operation from the container to the host, because an undesired glob operation occurs. An attacker could create a container image containing particular symlinks that, when copied by a victim user to the host filesystem, may overwrite existing files with others from the host.
Red Hat
podman: resolving symlink in host filesystem leads to unexpected results of copy operation
vendor_redhat·2019-08-22·CVSS 5.5
CVE-2019-18466 [MEDIUM] CWE-59 podman: resolving symlink in host filesystem leads to unexpected results of copy operation
podman: resolving symlink in host filesystem leads to unexpected results of copy operation
An issue was discovered in Podman in libpod before 1.6.0. It resolves a symlink in the host context during a copy operation from the container to the host, because an undesired glob operation occurs. An attacker could create a container image containing particular symlinks that, when copied by a victim user to the host filesystem, may overwrite existing files with others from the host.
It was discovered that podman resolves a symlink in the host context during a copy operation from the container to the host. An attacker could create a container image containing particular symlinks that, when copied by a victim user to the host filesystem, may overwrite existing files with others from the host.
Sta
Debian
CVE-2019-18466: libpod - An issue was discovered in Podman in libpod before 1.6.0. It resolves a symlink ...
vendor_debian·2019·CVSS 5.5
CVE-2019-18466 [MEDIUM] CVE-2019-18466: libpod - An issue was discovered in Podman in libpod before 1.6.0. It resolves a symlink ...
An issue was discovered in Podman in libpod before 1.6.0. It resolves a symlink in the host context during a copy operation from the container to the host, because an undesired glob operation occurs. An attacker could create a container image containing particular symlinks that, when copied by a victim user to the host filesystem, may overwrite existing files with others from the host.
Scope: local
bookworm: resolved
bullseye: resolved
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-18466 podman: resolving symlink in host filesystem leads to unexpected results of copy operation [fedora-all]
bugzilla·2019-09-23·CVSS 5.5
CVE-2019-18466 [MEDIUM] CVE-2019-18466 podman: resolving symlink in host filesystem leads to unexpected results of copy operation [fedora-all]
CVE-2019-18466 podman: resolving symlink in host filesystem leads to unexpected results of copy operation [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this
Bugzilla
CVE-2019-18466 podman: resolving symlink in host filesystem leads to unexpected results of copy operation
bugzilla·2019-08-22·CVSS 5.5
CVE-2019-18466 [MEDIUM] CVE-2019-18466 podman: resolving symlink in host filesystem leads to unexpected results of copy operation
CVE-2019-18466 podman: resolving symlink in host filesystem leads to unexpected results of copy operation
'podman cp' will resolve a carefully crafted symlink in host-filesystem space, yielding unexpected results when cp'ing from container to host. An attacker could create a container image containing particular symlinks that, when copied by a victim user to the host filesystem, may overwrite existing files with others from the host.
Upstream Issue:
https://github.com/containers/libpod/issues/3829
Discussion:
This is a duplicate of this issue https://bugzilla.redhat.com/show_bug.cgi?id=1741709
---
Upstream patch:
https://github.com/containers/libpod/commit/5c09c4d2947a759724f9d5aef6bac04317e03f7e
---
Created podman tracking bugs for this issue:
Affects: fedora-all [bug 1754354]
-
http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00040.htmlhttps://access.redhat.com/errata/RHSA-2019:4269https://bugzilla.redhat.com/show_bug.cgi?id=1744588https://github.com/containers/libpod/commit/5c09c4d2947a759724f9d5aef6bac04317e03f7ehttps://github.com/containers/libpod/compare/v1.5.1...v1.6.0https://github.com/containers/libpod/issues/3829http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00040.htmlhttps://access.redhat.com/errata/RHSA-2019:4269https://bugzilla.redhat.com/show_bug.cgi?id=1744588https://github.com/containers/libpod/commit/5c09c4d2947a759724f9d5aef6bac04317e03f7ehttps://github.com/containers/libpod/compare/v1.5.1...v1.6.0https://github.com/containers/libpod/issues/3829
2019-10-28
Published