#VU51962 UNIX symbolic link following in umoci - CVE-2021-29136
Published: April 7, 2021
umoci
umo.ci
Description
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to a symlink following issue when processing crafted images. A remote attacker can create a specially crafted image with symbolic link to a critical file on the system and overwrite it, when "umoci unpack" or "umoci raw unpack" is used.
Successful exploitation of this vulnerability may result in privilege escalation.