Improper input validation in Apache Ant - CVE-2018-10886

 

Improper input validation in Apache Ant - CVE-2018-10886

Published: July 25, 2018 / Updated: July 26, 2018


Vulnerability identifier: #VU13998
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-10886
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to create or overwrite arbitrary files on the target system.

The vulnerability exists due to the affected software allows archive files to be extracted outside of the target directory. A remote unauthenticated attacker can submit a specially crafted ZIP or TAR archive to an Ant build, trick the victim into extracting it, cause a file to be created outside the current working directory on the system and create or overwrite arbitrary files.


Affected software

Apache Ant
Debian Linux
Amazon Linux AMI
Opensuse
Fedora
ant

How to mitigate CVE-2018-10886

Update to version 1.9.12.

Apache Ant - update to 1.9.12
ant - addressed in versions 1.10.1-10.fc27, 1.10.1-10.fc28, 1.10-20180629154141.819b5873

External References

Related Security Bulletins