Vulnerability Description
A directory traversal issue was found in reposync, a part of yum-utils, where reposync fails to sanitize paths in remote repository configuration files. If an attacker controls a repository, they may be able to copy files outside of the destination directory on the targeted system via path traversal. If reposync is running with heightened privileges on a targeted system, this flaw could potentially result in system compromise via the overwriting of critical system files. Version 1.1.31 and older are believed to be affected.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Rpm | Yum-Utils | <= 1.1.31 |
| Redhat | Virtualization | 4.0 |
| Redhat | Enterprise Linux Desktop | 6.0 |
| Redhat | Enterprise Linux Server | 6.0 |
| Redhat | Enterprise Linux Workstation | 6.0 |
Related Weaknesses (CWE)
References
- http://www.securitytracker.com/id/1041594Third Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2018:2284Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2285Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2626Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10897Issue TrackingPatchThird Party Advisory
- https://github.com/rpm-software-management/yum-utils/commit/6a8de061f8fdc885e74ePatchThird Party Advisory
- https://github.com/rpm-software-management/yum-utils/commit/7554c0133eb830a71dc0PatchThird Party Advisory
- https://github.com/rpm-software-management/yum-utils/pull/43Third Party Advisory
- https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxurThird Party Advisory
- http://www.securitytracker.com/id/1041594Third Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2018:2284Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2285Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2626Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10897Issue TrackingPatchThird Party Advisory
- https://github.com/rpm-software-management/yum-utils/commit/6a8de061f8fdc885e74ePatchThird Party Advisory
FAQ
What is CVE-2018-10897?
CVE-2018-10897 is a vulnerability with a CVSS score of 8.1 (HIGH). A directory traversal issue was found in reposync, a part of yum-utils, where reposync fails to sanitize paths in remote repository configuration files. If an attacker controls a repository, they may ...
How severe is CVE-2018-10897?
CVE-2018-10897 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-10897?
Check the references section above for vendor advisories and patch information. Affected products include: Rpm Yum-Utils, Redhat Virtualization, Redhat Enterprise Linux Desktop, Redhat Enterprise Linux Server, Redhat Enterprise Linux Workstation.