vulnerability

Amazon Linux AMI 2: CVE-2018-10897: Security patch for yum-utils (ALAS-2018-1063)

Severity
9
CVSS
(AV:N/AC:M/Au:N/C:C/I:C/A:C)
Published
Aug 1, 2018
Added
Apr 27, 2020
Modified
Nov 27, 2024

Description

A directory traversal issue was found in reposync, a part of yum-utils, where reposync fails to sanitize paths in remote repository configuration files. If an attacker controls a repository, they may be able to copy files outside of the destination directory on the targeted system via path traversal. If reposync is running with heightened privileges on a targeted system, this flaw could potentially result in system compromise via the overwriting of critical system files. Version 1.1.31 and older are believed to be affected.

Solution(s)

amazon-linux-ami-2-upgrade-yum-networkmanager-dispatcheramazon-linux-ami-2-upgrade-yum-plugin-aliasesamazon-linux-ami-2-upgrade-yum-plugin-auto-update-debug-infoamazon-linux-ami-2-upgrade-yum-plugin-changelogamazon-linux-ami-2-upgrade-yum-plugin-copramazon-linux-ami-2-upgrade-yum-plugin-fastestmirroramazon-linux-ami-2-upgrade-yum-plugin-filter-dataamazon-linux-ami-2-upgrade-yum-plugin-fs-snapshotamazon-linux-ami-2-upgrade-yum-plugin-keysamazon-linux-ami-2-upgrade-yum-plugin-list-dataamazon-linux-ami-2-upgrade-yum-plugin-localamazon-linux-ami-2-upgrade-yum-plugin-merge-confamazon-linux-ami-2-upgrade-yum-plugin-ovlamazon-linux-ami-2-upgrade-yum-plugin-post-transaction-actionsamazon-linux-ami-2-upgrade-yum-plugin-pre-transaction-actionsamazon-linux-ami-2-upgrade-yum-plugin-prioritiesamazon-linux-ami-2-upgrade-yum-plugin-protectbaseamazon-linux-ami-2-upgrade-yum-plugin-psamazon-linux-ami-2-upgrade-yum-plugin-remove-with-leavesamazon-linux-ami-2-upgrade-yum-plugin-rpm-warm-cacheamazon-linux-ami-2-upgrade-yum-plugin-show-leavesamazon-linux-ami-2-upgrade-yum-plugin-tmprepoamazon-linux-ami-2-upgrade-yum-plugin-tsflagsamazon-linux-ami-2-upgrade-yum-plugin-upgrade-helperamazon-linux-ami-2-upgrade-yum-plugin-verifyamazon-linux-ami-2-upgrade-yum-plugin-versionlockamazon-linux-ami-2-upgrade-yum-updateonbootamazon-linux-ami-2-upgrade-yum-utils
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.