CVE-2018-1000849
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Alpine Linux version Versions prior to 2.6.10, 2.7.6, and 2.10.1 contains a Other/Unknown vulnerability in apk-tools (Alpine Linux' package manager) that can result in Remote Code Execution. This attack appear to be exploitable via A specially crafted APK-file can cause apk to write arbitrary data to an attacker-specified file, due to bugs in handling long link target name and the way a regular file is extracted.. This vulnerability appears to have been fixed in 2.6.10, 2.7.6, and 2.10.1.
Alpine Linux, en versiones anteriores a la 2.6.10, 2.7.6 y 2.10.1, contiene una vulnerabilidad desconocida en apk-tools (el gestor de paquetes de Alpine Linux) que puede resultar en la ejecución remota de código. Este ataque parece ser explotable mediante un archivo APK especialmente manipulado, que puede provocar que la apk escriba datos arbitrarios en un archivo especificado por el atacante, debido a errores en el manejo de un nombre largo objetivo y la forma en la que se extrae un archivo normal. La vulnerabilidad parece haber sido solucionada en las versiones 2.6.10, 2.7.6 y 2.10.1.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-12-20 CVE Reserved
- 2018-12-20 CVE Published
- 2024-09-17 CVE Updated
- 2024-09-17 First Exploit
- 2024-10-29 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-20: Improper Input Validation
CAPEC
References (3)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://justi.cz/security/2018/09/13/alpine-apk-rce.html | 2024-09-17 |
URL | Date | SRC |
---|---|---|
https://git.alpinelinux.org/cgit/apk-tools/commit/?id=6484ed9849f03971eb48ee1fdc21a2f128247eb1 | 2020-03-18 |
URL | Date | SRC |
---|---|---|
https://alpinelinux.org/posts/Alpine-3.8.1-released.html | 2020-03-18 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Alpinelinux Search vendor "Alpinelinux" | Alpine Linux Search vendor "Alpinelinux" for product "Alpine Linux" | < 2.6.10 Search vendor "Alpinelinux" for product "Alpine Linux" and version " < 2.6.10" | - |
Affected
| ||||||
Alpinelinux Search vendor "Alpinelinux" | Alpine Linux Search vendor "Alpinelinux" for product "Alpine Linux" | >= 2.7.0 < 2.7.6 Search vendor "Alpinelinux" for product "Alpine Linux" and version " >= 2.7.0 < 2.7.6" | - |
Affected
| ||||||
Alpinelinux Search vendor "Alpinelinux" | Alpine Linux Search vendor "Alpinelinux" for product "Alpine Linux" | >= 2.7.7 < 2.10.1 Search vendor "Alpinelinux" for product "Alpine Linux" and version " >= 2.7.7 < 2.10.1" | - |
Affected
|