SB2018080718 - Privilege escalation in yum-utils



SB2018080718 - Privilege escalation in yum-utils

Published: August 7, 2018

Security Bulletin ID SB2018080718
Severity
Low
Patch available
NO
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Path traversal (CVE-ID: CVE-2018-10897)

The vulnerability allows a remote attacker to gain elevated privileges on the target system.

The vulnerability exists in reposync, a part of yum-utils due to insufficient sanitization of paths in remote repository configuration files. A remote unauthenticated attacker can conduct directory traversal attack, copy files outside of the destination directory and gain elevated privileges to conduct further attacks.


Remediation

Cybersecurity Help is not aware of any official remediation provided by the vendor.