CVE-2019-18466
podman: resolving symlink in host filesystem leads to unexpected results of copy operation
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
An issue was discovered in Podman in libpod before 1.6.0. It resolves a symlink in the host context during a copy operation from the container to the host, because an undesired glob operation occurs. An attacker could create a container image containing particular symlinks that, when copied by a victim user to the host filesystem, may overwrite existing files with others from the host.
Se descubrió un problema en Podman en libpod versiones anteriores a la versión 1.6.0. Resuelve un enlace simbólico (symlink) en el contexto del host durante una operación de copia desde el contenedor hacia el host, porque se produce una operación glob no deseada. Un atacante podría crear una imagen de contenedor que contenga enlaces simbólicos particulares que, cuando sean copiados por parte de un usuario víctima hacia el sistema de archivos del host, pueden sobrescribir los archivos existentes con otros del host.
It was discovered that podman resolves a symlink in the host context during a copy operation from the container to the host. An attacker could create a container image containing particular symlinks that, when copied by a victim user to the host filesystem, may overwrite existing files with others from the host.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-10-28 CVE Reserved
- 2019-10-28 CVE Published
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- 2024-10-21 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-59: Improper Link Resolution Before File Access ('Link Following')
CAPEC
References (7)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://github.com/containers/libpod/issues/3829 | 2024-08-05 |
URL | Date | SRC |
---|---|---|
https://github.com/containers/libpod/commit/5c09c4d2947a759724f9d5aef6bac04317e03f7e | 2020-01-15 | |
https://github.com/containers/libpod/compare/v1.5.1...v1.6.0 | 2020-01-15 |
URL | Date | SRC |
---|---|---|
http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00040.html | 2020-01-15 | |
https://access.redhat.com/errata/RHSA-2019:4269 | 2020-01-15 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1744588 | 2020-01-15 | |
https://access.redhat.com/security/cve/CVE-2019-18466 | 2020-04-01 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Libpod Project Search vendor "Libpod Project" | Libpod Search vendor "Libpod Project" for product "Libpod" | < 1.6.0 Search vendor "Libpod Project" for product "Libpod" and version " < 1.6.0" | - |
Affected
|