Path traversal in yum-utils - CVE-2018-10897
Published: August 6, 2018 / Updated: August 7, 2018
Vulnerability details
The vulnerability allows a remote attacker to gain elevated privileges on the target system.
The vulnerability exists in reposync, a part of yum-utils due to insufficient sanitization of paths in remote repository configuration files. A remote unauthenticated attacker can conduct directory traversal attack, copy files outside of the destination directory and gain elevated privileges to conduct further attacks.
Affected software
Amazon Linux AMI
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux for Power
Fedora
Red Hat Virtualization
Red Hat Virtualization Host
libcomps
createrepo_c
libdnf
yum-utils
librepo
dnf-plugins-extras
dnf-plugins-core
dnf
How to mitigate CVE-2018-10897
createrepo_c - update to 0.12.1-1.fc29
libdnf - update to 0.26.0-1.fc29
yum-utils - addressed in versions 1.1.31-514.fc27, 1.1.31-515.fc28, 1.1.31-517.fc29
librepo - update to 1.9.4-1.fc29
dnf-plugins-extras - update to 4.0.2-1.fc29
dnf-plugins-core - update to 4.0.4-1.fc29
dnf - update to 4.1.0-1.fc29
External References
Related Security Bulletins
- Privilege escalation in yum-utils
- Amazon Linux AMI update for yum-utils
- Red Hat update for yum-utils
- Red Hat update for yum-utils
- Red Hat update for yum-utils
- Fedora 29 update for yum-utils
- Fedora 28 update for yum-utils
- Fedora 27 update for yum-utils
- Fedora 29 update for createrepo_c, dnf, dnf-plugins-core, dnf-plugins-extras, libcomps, libdnf, librepo