SB2019072329 - Improper Link Resolution Before File Access (\'Link Following\') in patch (Alpine package)
Published: July 23, 2019
Security Bulletin ID
SB2019072329
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Local access
Highest impact
Data manipulation
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper Link Resolution Before File Access ('Link Following') (CVE-ID: CVE-2019-13636)
The vulnerability allows a local user to gain unauthorized access to files or directories on a targeted system.
The vulnerability exists due to the software mishandles the following of symlinks in certain cases other than input files in the "inp.c" and "util.c" files. A local authenticated user can gain unauthorized access to read or modify files and directories on a targeted system.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=eb88ff152557254bd38fbe358892d73f97a09e6b
- https://git.alpinelinux.org/aports/commit/?id=1d883b90c2617f701a473458f6bea95c5488513b
- https://git.alpinelinux.org/aports/commit/?id=38b6dd1c340446b8eb31aefaf5396ba65ca94369
- https://git.alpinelinux.org/aports/commit/?id=3f413a6b4f89e4d069b26f1e2302a6c914e02b6e
- https://git.alpinelinux.org/aports/commit/?id=858c1e50bc7b69a652bedc684cf06dd025afeeab
- https://git.alpinelinux.org/aports/commit/?id=88e814fbbdb9a9a335964ae6dac9caa730df1cbf