UNIX symbolic link following in umoci - CVE-2021-29136
Published: April 7, 2021
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to a symlink following issue when processing crafted images. A remote attacker can create a specially crafted image with symbolic link to a critical file on the system and overwrite it, when "umoci unpack" or "umoci raw unpack" is used.
Successful exploitation of this vulnerability may result in privilege escalation.
Affected software
Singularity
SUSE Manager Retail Branch Server
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Server
SUSE Enterprise Storage
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Containers
SUSE Linux Enterprise Module for Basesystem
openEuler
umoci
umoci-help
How to mitigate CVE-2021-29136
Singularity - update to 3.7.3
umoci - update to 0.4.5-4
umoci-help - update to 0.4.5-4
umoci - addressed in versions 0.4.6-3.9.1, 0.4.7-3.12.1