Path traversal in librepo - CVE-2020-14352

 

Path traversal in librepo - CVE-2020-14352

Published: August 30, 2020 / Updated: October 9, 2020


Vulnerability identifier: #VU47485
CSH Severity: Medium
CVSS v4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-14352
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform directory traversal attacks.

The vulnerability exists due to input validation error when processing directory traversal sequences in remote repository metadata. A remote attacker with control over the repository can trick the victim into downloading software and copy files outside of the destination directory on the targeted system. Successful exploitation of the vulnerability may result in system compromise.


Affected software

librepo
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
CentOS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
SUSE Linux
Opensuse
openEuler
Fedora
createrepo_c
libdnf
librepo (Red Hat package)
librepo-debuginfo
librepo-devel
python3-librepo
librepo
python2-librepo
librepo-debugsource
dnf-plugins-extras
dnf-plugins-core
dnf
livecd-tools
OpenShift Virtualization
Red Hat OpenShift Container Platform

How to mitigate CVE-2020-14352

Install update from vendor's website.

librepo - update to 1.12.1
createrepo_c - addressed in versions 0.16.1-1.fc33, 0.16.1-2.fc32
libdnf - update to 0.54.2-1.fc32
librepo (Red Hat package) - addressed in versions 1.8.1-8.el7_9, 1.9.2-2.el8_0, 1.10.3-4.el8_1, 1.11.0-3.el8_2
librepo-debuginfo - update to 1.12.0-2
librepo-devel - update to 1.12.0-2
python3-librepo - update to 1.12.0-2
librepo - update to 1.12.0-2
python2-librepo - update to 1.12.0-2
librepo-debugsource - update to 1.12.0-2
librepo - addressed in versions 1.12.1-1.fc31, 1.12.1-1.fc32, 1.12.1-1.fc33
OpenShift Virtualization - update to 2.4.2
dnf-plugins-extras - addressed in versions 4.0.12-1.fc32, 4.0.12-1.fc33
dnf-plugins-core - addressed in versions 4.0.18-1.fc32, 4.0.18-1.fc33
Red Hat OpenShift Container Platform - update to 4.3.40
dnf - update to 4.4.0-1.fc32
livecd-tools - addressed in versions 27.1-8.fc32, 27.1-8.fc33

External References

Related Security Bulletins