A flaw was found in librepo in versions before 1.12.1. A directory traversal vulnerability was found where it failed to sanitize paths in remote repository metadata. An attacker controlling a remote repository may be able to copy files outside of the destination directory on the targeted system via path traversal. This flaw could potentially result in system compromise via the overwriting of critical system files. The highest threat from this flaw is to users that make use of untrusted third-party repositories.
CVSS Details
- CVSS 3.1 Base Score: 8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade librepoUpgrade librepo-develUpgrade librepo-debuginfoUpgrade python-librepo | Dec 10, 2020 | Aug 30, 2020 |
| Centos_linux | — | Upgrade librepo-debugsourceUpgrade python3-librepoUpgrade python3-librepo-debuginfoUpgrade python-librepoUpgrade librepo-develUpgrade librepoUpgrade librepo-debuginfo | Sep 9, 2020 | Aug 30, 2020 |
| Huawei Euleros 2_0_sp8 | — | Upgrade librepoUpgrade python2-librepoUpgrade python3-librepo | Nov 26, 2020 | Aug 30, 2020 |
| Huawei Euleros 2_0_sp9 | — | Upgrade python3-librepoUpgrade librepo | Nov 3, 2020 | Aug 30, 2020 |
| Oracle_linux | — | Upgrade python-librepoUpgrade librepo-develUpgrade python3-librepoUpgrade librepo | Sep 10, 2020 | Aug 13, 2020 |
| Redhat Openshift | — | Upgrade redhat-coreos | Dec 29, 2020 | Aug 30, 2020 |
| Redhat_linux | — | Upgrade librepo-debuginfoUpgrade python3-librepoUpgrade python3-librepo-debuginfoUpgrade python-librepoUpgrade librepo-develUpgrade librepo-debugsourceUpgrade librepo | Sep 9, 2020 | Aug 30, 2020 |
| Suse | — | Upgrade librepo0Upgrade python3-librepoUpgrade librepo-devel | Aug 31, 2020 | Aug 30, 2020 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Aug 30, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub