CVE-2020-1726
published 2020-02-11CVE-2020-1726: A flaw was discovered in Podman where it incorrectly allows containers when created to overwrite existing files in volumes, even if they are mounted as…
PriorityP434medium5.9CVSS 3.1
AVNACHPRNUINSUCNIHAN
EPSS
1.85%
76.7th percentile
A flaw was discovered in Podman where it incorrectly allows containers when created to overwrite existing files in volumes, even if they are mounted as read-only. When a user runs a malicious container or a container based on a malicious image with an attached volume that is used for the first time, it is possible to trigger the flaw and overwrite files in the volume.This issue was introduced in version 1.6.0.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libpod | < libpod 1.6.4+dfsg1-3 (bookworm) | libpod 1.6.4+dfsg1-3 (bookworm) |
| github.com | containers_libpod | >= 1.6.0 | — |
| github.com | containers_libpod_v2 | >= 0 < 2.0.6 | 2.0.6 |
| github.com | containers_podman | >= 1.6.0 < 2.0.6 | 2.0.6 |
| github.com | containers_podman_v2 | >= 0 < 2.0.6 | 2.0.6 |
| libpod_project | libpod | — | — |
| libpod_project | libpod | >= 0 < 1.6.4+dfsg1-3 | 1.6.4+dfsg1-3 |
| libpod_project | libpod | >= 0 < 1.6.4+dfsg1-3 | 1.6.4+dfsg1-3 |
| redhat | enterprise_linux | — | — |
| redhat | openshift_container_platform | — | — |
| the | podman | — | — |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:P
osv5.9MEDIUM
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Podman has Files or Directories Accessible to External Parties in github.com/containers/libpod
osv·2024-08-20
CVE-2020-1726 Podman has Files or Directories Accessible to External Parties in github.com/containers/libpod
Podman has Files or Directories Accessible to External Parties in github.com/containers/libpod
Podman has Files or Directories Accessible to External Parties in github.com/containers/libpod
GHSA
Podman has Files or Directories Accessible to External Parties
ghsa·2022-05-24
CVE-2020-1726 [MEDIUM] CWE-552 Podman has Files or Directories Accessible to External Parties
Podman has Files or Directories Accessible to External Parties
A flaw was discovered in Podman where it incorrectly allows containers when created to overwrite existing files in volumes, even if they are mounted as read-only. When a user runs a malicious container or a container based on a malicious image with an attached volume that is used for the first time, it is possible to trigger the flaw and overwrite files in the volume. This issue was introduced in version 1.6.0.
OSV
Podman has Files or Directories Accessible to External Parties
osv·2022-05-24
CVE-2020-1726 [MEDIUM] Podman has Files or Directories Accessible to External Parties
Podman has Files or Directories Accessible to External Parties
A flaw was discovered in Podman where it incorrectly allows containers when created to overwrite existing files in volumes, even if they are mounted as read-only. When a user runs a malicious container or a container based on a malicious image with an attached volume that is used for the first time, it is possible to trigger the flaw and overwrite files in the volume. This issue was introduced in version 1.6.0.
OSV
CVE-2020-1726: A flaw was discovered in Podman where it incorrectly allows containers when created to overwrite existing files in volumes, even if they are mounted a
osv·2020-02-11·CVSS 5.9
CVE-2020-1726 [MEDIUM] CVE-2020-1726: A flaw was discovered in Podman where it incorrectly allows containers when created to overwrite existing files in volumes, even if they are mounted a
A flaw was discovered in Podman where it incorrectly allows containers when created to overwrite existing files in volumes, even if they are mounted as read-only. When a user runs a malicious container or a container based on a malicious image with an attached volume that is used for the first time, it is possible to trigger the flaw and overwrite files in the volume.This issue was introduced in version 1.6.0.
Red Hat
podman: incorrectly allows existing files in volumes to be overwritten by a container when it is created
vendor_redhat·2020-02-11·CVSS 5.9
CVE-2020-1726 [MEDIUM] CWE-552 podman: incorrectly allows existing files in volumes to be overwritten by a container when it is created
podman: incorrectly allows existing files in volumes to be overwritten by a container when it is created
A flaw was discovered in Podman where it incorrectly allows containers when created to overwrite existing files in volumes, even if they are mounted as read-only. When a user runs a malicious container or a container based on a malicious image with an attached volume that is used for the first time, it is possible to trigger the flaw and overwrite files in the volume.This issue was introduced in version 1.6.0.
A flaw was discovered in Podman where it incorrectly allows containers when created to overwrite existing files in volumes, even if they are mounted as read-only. When a user runs a malicious container or a container based on a malicious image with an attached volume that is use
Debian
CVE-2020-1726: libpod - A flaw was discovered in Podman where it incorrectly allows containers when crea...
vendor_debian·2020·CVSS 5.9
CVE-2020-1726 [MEDIUM] CVE-2020-1726: libpod - A flaw was discovered in Podman where it incorrectly allows containers when crea...
A flaw was discovered in Podman where it incorrectly allows containers when created to overwrite existing files in volumes, even if they are mounted as read-only. When a user runs a malicious container or a container based on a malicious image with an attached volume that is used for the first time, it is possible to trigger the flaw and overwrite files in the volume.This issue was introduced in version 1.6.0.
Scope: local
bookworm: resolved (fixed in 1.6.4+dfsg1-3)
bullseye: resolved (fixed in 1.6.4+dfsg1-3)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-27761 ImageMagick: outside the range of representable values of type 'unsigned long' at coders/palm.c
bugzilla·2020-11-04·CVSS 3.3
CVE-2020-27761 [LOW] CVE-2020-27761 ImageMagick: outside the range of representable values of type 'unsigned long' at coders/palm.c
CVE-2020-27761 ImageMagick: outside the range of representable values of type 'unsigned long' at coders/palm.c
In ImageMagick, there are three outside the range of representable values of type 'unsigned long' at coders/palm.c.
Reference:
https://github.com/ImageMagick/ImageMagick/issues/1726
Upstream patch:
https://github.com/ImageMagick/ImageMagick/commit/db5e12e24f1378ce8c93a5c35991dcdd23a67bb0
Discussion:
Acknowledgments:
Name: Suhwan Song (Seoul National University)
---
Flaw summary:
WritePALMImage() in /coders/palm.c used size_t casts in several areas of a calculation which could lead to values outside the range of representable type `unsigned long` undefined behavior when a crafted input file was processed by ImageMagick. The patch casts to `ssize_t` instead to avoid this is
Bugzilla
CVE-2020-1726 podman: incorrectly allows existing files in volumes to be overwritten by a container when it is created
bugzilla·2020-02-10·CVSS 5.9
CVE-2020-1726 [MEDIUM] CVE-2020-1726 podman: incorrectly allows existing files in volumes to be overwritten by a container when it is created
CVE-2020-1726 podman: incorrectly allows existing files in volumes to be overwritten by a container when it is created
podman incorrectly allows containers, when created, to populate volumes that already have existing data inside. A malicious container image may use this flaw to overwrite existing files in a volume, even if it is mounted in read-only mode. The attack is possible only the first time a volume is used.
Discussion:
Vulnerability introduced in upstream commit:
https://github.com/containers/libpod/commit/997c4b56ed2121726e966afe9a102ed16ba78f93
First vulnerable upstream version is v1.6.0, which includes the above commit.
---
Function mountNamedVolume() is responsible for copying the content of the destination volume directory from the container to the volume. The copy (and
http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00097.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-09/msg00103.htmlhttps://access.redhat.com/errata/RHSA-2020:0680https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1726http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00097.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-09/msg00103.htmlhttps://access.redhat.com/errata/RHSA-2020:0680https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1726
2020-02-11
Published