CVE-2018-10897

Description

A directory traversal issue was found in reposync, a part of yum-utils, where reposync fails to sanitize paths in remote repository configuration files. If an attacker controls a repository, they may be able to copy files outside of the destination directory on the targeted system via path traversal. If reposync is running with heightened privileges on a targeted system, this flaw could potentially result in system compromise via the overwriting of critical system files. Version 1.1.31 and older are believed to be affected.

Risk Information

Base Score
8.1
MODERATE
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
2.619

Associated Vulnerability

VulnerabilityOS Platform
Yum-utils security update (CESA-2018:2284) yum-utils-1.1.30-42.el6_10.noarch.rpmLinux
Yum-utils security update (CESA-2018:2284) yum-plugin-ps-1.1.30-42.el6_10.noarch.rpmLinux
Yum-utils security update (CESA-2018:2284) yum-plugin-ovl-1.1.30-42.el6_10.noarch.rpmLinux
Yum-utils security update (CESA-2018:2284) yum-plugin-keys-1.1.30-42.el6_10.noarch.rpmLinux
Yum-utils security update (CESA-2018:2284) yum-plugin-local-1.1.30-42.el6_10.noarch.rpmLinux
Yum-utils security update (CESA-2018:2284) yum-updateonboot-1.1.30-42.el6_10.noarch.rpmLinux
Yum-utils security update (CESA-2018:2284) yum-plugin-verify-1.1.30-42.el6_10.noarch.rpmLinux
Yum-utils security update (CESA-2018:2284) yum-plugin-aliases-1.1.30-42.el6_10.noarch.rpmLinux
Yum-utils security update (CESA-2018:2284) yum-plugin-tmprepo-1.1.30-42.el6_10.noarch.rpmLinux
Yum-utils security update (CESA-2018:2284) yum-plugin-tsflags-1.1.30-42.el6_10.noarch.rpmLinux
Yum-utils security update (CESA-2018:2284) yum-plugin-security-1.1.30-42.el6_10.noarch.rpmLinux
Yum-utils security update (CESA-2018:2284) yum-plugin-changelog-1.1.30-42.el6_10.noarch.rpmLinux
Yum-utils security update (CESA-2018:2284) yum-plugin-list-data-1.1.30-42.el6_10.noarch.rpmLinux
Yum-utils security update (CESA-2018:2284) yum-plugin-merge-conf-1.1.30-42.el6_10.noarch.rpmLinux
Yum-utils security update (CESA-2018:2284) yum-plugin-priorities-1.1.30-42.el6_10.noarch.rpmLinux
Yum-utils security update (CESA-2018:2284) yum-plugin-filter-data-1.1.30-42.el6_10.noarch.rpmLinux
Yum-utils security update (CESA-2018:2284) yum-plugin-fs-snapshot-1.1.30-42.el6_10.noarch.rpmLinux
Yum-utils security update (CESA-2018:2284) yum-plugin-protectbase-1.1.30-42.el6_10.noarch.rpmLinux
Yum-utils security update (CESA-2018:2284) yum-plugin-show-leaves-1.1.30-42.el6_10.noarch.rpmLinux
Yum-utils security update (CESA-2018:2284) yum-plugin-versionlock-1.1.30-42.el6_10.noarch.rpmLinux
Yum-utils security update (CESA-2018:2284) yum-plugin-fastestmirror-1.1.30-42.el6_10.noarch.rpmLinux
Yum-utils security update (CESA-2018:2284) yum-plugin-rpm-warm-cache-1.1.30-42.el6_10.noarch.rpmLinux
Yum-utils security update (CESA-2018:2284) yum-plugin-upgrade-helper-1.1.30-42.el6_10.noarch.rpmLinux
Yum-utils security update (CESA-2018:2284) yum-NetworkManager-dispatcher-1.1.30-42.el6_10.noarch.rpmLinux
Yum-utils security update (CESA-2018:2284) yum-plugin-remove-with-leaves-1.1.30-42.el6_10.noarch.rpmLinux
Yum-utils security update (CESA-2018:2284) yum-plugin-auto-update-debug-info-1.1.30-42.el6_10.noarch.rpmLinux
Yum-utils security update (CESA-2018:2284) yum-plugin-post-transaction-actions-1.1.30-42.el6_10.noarch.rpmLinux
(RHSA-2018:2284) Important: yum-utils security update yum-NetworkManager-dispatcher-1.1.30-42.el6_10.noarch.rpmLinux
(RHSA-2018:2284) Important: yum-utils security update yum-plugin-aliases-1.1.30-42.el6_10.noarch.rpmLinux
(RHSA-2018:2284) Important: yum-utils security update yum-plugin-auto-update-debug-info-1.1.30-42.el6_10.noarch.rpmLinux
(RHSA-2018:2284) Important: yum-utils security update yum-plugin-changelog-1.1.30-42.el6_10.noarch.rpmLinux
(RHSA-2018:2284) Important: yum-utils security update yum-plugin-fastestmirror-1.1.30-42.el6_10.noarch.rpmLinux
(RHSA-2018:2284) Important: yum-utils security update yum-plugin-filter-data-1.1.30-42.el6_10.noarch.rpmLinux
(RHSA-2018:2284) Important: yum-utils security update yum-plugin-fs-snapshot-1.1.30-42.el6_10.noarch.rpmLinux
(RHSA-2018:2284) Important: yum-utils security update yum-plugin-keys-1.1.30-42.el6_10.noarch.rpmLinux
(RHSA-2018:2284) Important: yum-utils security update yum-plugin-list-data-1.1.30-42.el6_10.noarch.rpmLinux
(RHSA-2018:2284) Important: yum-utils security update yum-plugin-local-1.1.30-42.el6_10.noarch.rpmLinux
(RHSA-2018:2284) Important: yum-utils security update yum-plugin-merge-conf-1.1.30-42.el6_10.noarch.rpmLinux
(RHSA-2018:2284) Important: yum-utils security update yum-plugin-ovl-1.1.30-42.el6_10.noarch.rpmLinux
(RHSA-2018:2284) Important: yum-utils security update yum-plugin-post-transaction-actions-1.1.30-42.el6_10.noarch.rpmLinux
(RHSA-2018:2284) Important: yum-utils security update yum-plugin-priorities-1.1.30-42.el6_10.noarch.rpmLinux
(RHSA-2018:2284) Important: yum-utils security update yum-plugin-protectbase-1.1.30-42.el6_10.noarch.rpmLinux
(RHSA-2018:2284) Important: yum-utils security update yum-plugin-ps-1.1.30-42.el6_10.noarch.rpmLinux
(RHSA-2018:2284) Important: yum-utils security update yum-plugin-remove-with-leaves-1.1.30-42.el6_10.noarch.rpmLinux
(RHSA-2018:2284) Important: yum-utils security update yum-plugin-rpm-warm-cache-1.1.30-42.el6_10.noarch.rpmLinux
(RHSA-2018:2284) Important: yum-utils security update yum-plugin-security-1.1.30-42.el6_10.noarch.rpmLinux
(RHSA-2018:2284) Important: yum-utils security update yum-plugin-show-leaves-1.1.30-42.el6_10.noarch.rpmLinux
(RHSA-2018:2284) Important: yum-utils security update yum-plugin-tmprepo-1.1.30-42.el6_10.noarch.rpmLinux
(RHSA-2018:2284) Important: yum-utils security update yum-plugin-tsflags-1.1.30-42.el6_10.noarch.rpmLinux
(RHSA-2018:2284) Important: yum-utils security update yum-plugin-upgrade-helper-1.1.30-42.el6_10.noarch.rpmLinux
(RHSA-2018:2284) Important: yum-utils security update yum-plugin-verify-1.1.30-42.el6_10.noarch.rpmLinux
(RHSA-2018:2284) Important: yum-utils security update yum-plugin-versionlock-1.1.30-42.el6_10.noarch.rpmLinux
(RHSA-2018:2284) Important: yum-utils security update yum-updateonboot-1.1.30-42.el6_10.noarch.rpmLinux
(RHSA-2018:2284) Important: yum-utils security update yum-utils-1.1.30-42.el6_10.noarch.rpmLinux
(RHSA-2018:2285) Important: yum-utils security update yum-NetworkManager-dispatcher-1.1.31-46.el7_5.noarch.rpmLinux
(RHSA-2018:2285) Important: yum-utils security update yum-plugin-aliases-1.1.31-46.el7_5.noarch.rpmLinux
(RHSA-2018:2285) Important: yum-utils security update yum-plugin-auto-update-debug-info-1.1.31-46.el7_5.noarch.rpmLinux
(RHSA-2018:2285) Important: yum-utils security update yum-plugin-changelog-1.1.31-46.el7_5.noarch.rpmLinux
(RHSA-2018:2285) Important: yum-utils security update yum-plugin-copr-1.1.31-46.el7_5.noarch.rpmLinux
(RHSA-2018:2285) Important: yum-utils security update yum-plugin-fastestmirror-1.1.31-46.el7_5.noarch.rpmLinux
(RHSA-2018:2285) Important: yum-utils security update yum-plugin-filter-data-1.1.31-46.el7_5.noarch.rpmLinux
(RHSA-2018:2285) Important: yum-utils security update yum-plugin-fs-snapshot-1.1.31-46.el7_5.noarch.rpmLinux
(RHSA-2018:2285) Important: yum-utils security update yum-plugin-keys-1.1.31-46.el7_5.noarch.rpmLinux
(RHSA-2018:2285) Important: yum-utils security update yum-plugin-list-data-1.1.31-46.el7_5.noarch.rpmLinux
(RHSA-2018:2285) Important: yum-utils security update yum-plugin-local-1.1.31-46.el7_5.noarch.rpmLinux
(RHSA-2018:2285) Important: yum-utils security update yum-plugin-merge-conf-1.1.31-46.el7_5.noarch.rpmLinux
(RHSA-2018:2285) Important: yum-utils security update yum-plugin-ovl-1.1.31-46.el7_5.noarch.rpmLinux
(RHSA-2018:2285) Important: yum-utils security update yum-plugin-post-transaction-actions-1.1.31-46.el7_5.noarch.rpmLinux
(RHSA-2018:2285) Important: yum-utils security update yum-plugin-pre-transaction-actions-1.1.31-46.el7_5.noarch.rpmLinux
(RHSA-2018:2285) Important: yum-utils security update yum-plugin-priorities-1.1.31-46.el7_5.noarch.rpmLinux
(RHSA-2018:2285) Important: yum-utils security update yum-plugin-protectbase-1.1.31-46.el7_5.noarch.rpmLinux
(RHSA-2018:2285) Important: yum-utils security update yum-plugin-ps-1.1.31-46.el7_5.noarch.rpmLinux
(RHSA-2018:2285) Important: yum-utils security update yum-plugin-remove-with-leaves-1.1.31-46.el7_5.noarch.rpmLinux
(RHSA-2018:2285) Important: yum-utils security update yum-plugin-rpm-warm-cache-1.1.31-46.el7_5.noarch.rpmLinux
(RHSA-2018:2285) Important: yum-utils security update yum-plugin-show-leaves-1.1.31-46.el7_5.noarch.rpmLinux
(RHSA-2018:2285) Important: yum-utils security update yum-plugin-tmprepo-1.1.31-46.el7_5.noarch.rpmLinux
(RHSA-2018:2285) Important: yum-utils security update yum-plugin-tsflags-1.1.31-46.el7_5.noarch.rpmLinux
(RHSA-2018:2285) Important: yum-utils security update yum-plugin-upgrade-helper-1.1.31-46.el7_5.noarch.rpmLinux
(RHSA-2018:2285) Important: yum-utils security update yum-plugin-verify-1.1.31-46.el7_5.noarch.rpmLinux
(RHSA-2018:2285) Important: yum-utils security update yum-plugin-versionlock-1.1.31-46.el7_5.noarch.rpmLinux
(RHSA-2018:2285) Important: yum-utils security update yum-updateonboot-1.1.31-46.el7_5.noarch.rpmLinux
(RHSA-2018:2285) Important: yum-utils security update yum-utils-1.1.31-46.el7_5.noarch.rpmLinux
yum-utils Security Update (ALAS-2018-1063) yum-utils-1.1.31-46.amzn2.0.1.noarch.rpmLinux
yum-utils Security Update (ALAS-2018-1063) yum-plugin-ps-1.1.31-46.amzn2.0.1.noarch.rpmLinux
yum-utils Security Update (ALAS-2018-1063) yum-plugin-ovl-1.1.31-46.amzn2.0.1.noarch.rpmLinux
yum-utils Security Update (ALAS-2018-1063) yum-plugin-copr-1.1.31-46.amzn2.0.1.noarch.rpmLinux
yum-utils Security Update (ALAS-2018-1063) yum-plugin-keys-1.1.31-46.amzn2.0.1.noarch.rpmLinux
yum-utils Security Update (ALAS-2018-1063) yum-plugin-local-1.1.31-46.amzn2.0.1.noarch.rpmLinux
yum-utils Security Update (ALAS-2018-1063) yum-updateonboot-1.1.31-46.amzn2.0.1.noarch.rpmLinux
yum-utils Security Update (ALAS-2018-1063) yum-plugin-verify-1.1.31-46.amzn2.0.1.noarch.rpmLinux
yum-utils Security Update (ALAS-2018-1063) yum-plugin-aliases-1.1.31-46.amzn2.0.1.noarch.rpmLinux
yum-utils Security Update (ALAS-2018-1063) yum-plugin-tmprepo-1.1.31-46.amzn2.0.1.noarch.rpmLinux
yum-utils Security Update (ALAS-2018-1063) yum-plugin-tsflags-1.1.31-46.amzn2.0.1.noarch.rpmLinux
yum-utils Security Update (ALAS-2018-1063) yum-plugin-changelog-1.1.31-46.amzn2.0.1.noarch.rpmLinux
yum-utils Security Update (ALAS-2018-1063) yum-plugin-list-data-1.1.31-46.amzn2.0.1.noarch.rpmLinux
yum-utils Security Update (ALAS-2018-1063) yum-plugin-merge-conf-1.1.31-46.amzn2.0.1.noarch.rpmLinux
yum-utils Security Update (ALAS-2018-1063) yum-plugin-priorities-1.1.31-46.amzn2.0.1.noarch.rpmLinux
yum-utils Security Update (ALAS-2018-1063) yum-plugin-filter-data-1.1.31-46.amzn2.0.1.noarch.rpmLinux
yum-utils Security Update (ALAS-2018-1063) yum-plugin-fs-snapshot-1.1.31-46.amzn2.0.1.noarch.rpmLinux
yum-utils Security Update (ALAS-2018-1063) yum-plugin-protectbase-1.1.31-46.amzn2.0.1.noarch.rpmLinux
yum-utils Security Update (ALAS-2018-1063) yum-plugin-show-leaves-1.1.31-46.amzn2.0.1.noarch.rpmLinux
yum-utils Security Update (ALAS-2018-1063) yum-plugin-versionlock-1.1.31-46.amzn2.0.1.noarch.rpmLinux
yum-utils Security Update (ALAS-2018-1063) yum-plugin-fastestmirror-1.1.31-46.amzn2.0.1.noarch.rpmLinux
yum-utils Security Update (ALAS-2018-1063) yum-plugin-rpm-warm-cache-1.1.31-46.amzn2.0.1.noarch.rpmLinux
yum-utils Security Update (ALAS-2018-1063) yum-plugin-upgrade-helper-1.1.31-46.amzn2.0.1.noarch.rpmLinux
yum-utils Security Update (ALAS-2018-1063) yum-NetworkManager-dispatcher-1.1.31-46.amzn2.0.1.noarch.rpmLinux
yum-utils Security Update (ALAS-2018-1063) yum-plugin-remove-with-leaves-1.1.31-46.amzn2.0.1.noarch.rpmLinux
yum-utils Security Update (ALAS-2018-1063) yum-plugin-auto-update-debug-info-1.1.31-46.amzn2.0.1.noarch.rpmLinux
yum-utils Security Update (ALAS-2018-1063) yum-plugin-pre-transaction-actions-1.1.31-46.amzn2.0.1.noarch.rpmLinux
yum-utils Security Update (ALAS-2018-1063) yum-plugin-post-transaction-actions-1.1.31-46.amzn2.0.1.noarch.rpmLinux
CVE-2018-10897NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234