An issue was discovered in Podman in libpod before 1.6.0. It resolves a symlink in the host context during a copy operation from the container to the host, because an undesired glob operation occurs. An attacker could create a container image containing particular symlinks that, when copied by a victim user to the host filesystem, may overwrite existing files with others from the host.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade oci-systemd-hookUpgrade oci-umount | May 13, 2022 | Oct 28, 2019 |
| Centos_linux | — | Upgrade podmanUpgrade oci-umountUpgrade skopeoUpgrade runcUpgrade podman-debuginfoUpgrade podman-remote-debuginfoUpgrade containers-commonUpgrade oci-umount-debugsourceUpgrade buildah-tests-debuginfoUpgrade runc-debugsourceUpgrade buildah-debuginfoUpgrade skopeo-testsUpgrade podman-remoteUpgrade fuse-overlayfs-debugsourceUpgrade runc-debuginfoUpgrade containernetworking-pluginsUpgrade container-selinuxUpgrade oci-systemd-hookUpgrade buildah-debugsourceUpgrade oci-umount-debuginfoUpgrade slirp4netns-debugsourceUpgrade oci-systemd-hook-debugsourceUpgrade podman-debugsourceUpgrade buildah-testsUpgrade skopeo-debuginfoUpgrade python-podman-apiUpgrade podman-dockerUpgrade containernetworking-plugins-debuginfoUpgrade containernetworking-plugins-debugsourceUpgrade podman-manpagesUpgrade cockpit-podmanUpgrade oci-systemd-hook-debuginfoUpgrade skopeo-debugsourceUpgrade toolboxUpgrade slirp4netns-debuginfoUpgrade buildahUpgrade fuse-overlayfsUpgrade slirp4netnsUpgrade podman-testsUpgrade fuse-overlayfs-debuginfo | Jan 20, 2020 | Oct 28, 2019 |
| Redhat_linux | — | Upgrade runc-debuginfoUpgrade container-selinuxUpgrade slirp4netns-debugsourceUpgrade buildah-debugsourceUpgrade oci-systemd-hook-debuginfoUpgrade podman-debugsourceUpgrade podman-debuginfoUpgrade skopeo-testsUpgrade podman-manpagesUpgrade oci-systemd-hook-debugsourceUpgrade oci-systemd-hookUpgrade podman-remoteUpgrade slirp4netns-debuginfoUpgrade podman-testsUpgrade containernetworking-plugins-debugsourceUpgrade podman-dockerUpgrade slirp4netnsUpgrade containernetworking-pluginsUpgrade oci-umount-debugsourceUpgrade runcUpgrade containernetworking-plugins-debuginfoUpgrade skopeo-debuginfoUpgrade oci-umountUpgrade buildah-tests-debuginfoUpgrade podman-remote-debuginfoUpgrade fuse-overlayfsUpgrade buildah-testsUpgrade cockpit-podmanUpgrade runc-debugsourceUpgrade podmanUpgrade fuse-overlayfs-debugsourceUpgrade skopeo-debugsourceUpgrade python-podman-apiUpgrade fuse-overlayfs-debuginfoUpgrade toolboxUpgrade containers-commonUpgrade buildahUpgrade oci-umount-debuginfoUpgrade buildah-debuginfoUpgrade skopeo | Jan 20, 2020 | Oct 28, 2019 |
| Rocky_linux | — | Upgrade oci-umount-debugsourceUpgrade oci-systemd-hookUpgrade oci-systemd-hook-debuginfoUpgrade oci-systemd-hook-debugsourceUpgrade oci-umount-debuginfoUpgrade oci-umount | Mar 12, 2024 | Oct 28, 2019 |
| Suse | — | Upgrade podmanUpgrade conmonUpgrade fuse-overlayfsUpgrade cniUpgrade cni-pluginsUpgrade podman-cni-config | Mar 31, 2020 | Oct 28, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub