A flaw was found in librepo in versions before 1.12.1. A directory traversal vulnerability was found where it failed to sanitize paths in remote repository metadata. An attacker controlling a remote repository may be able to copy files outside of the destination directory on the targeted system via path traversal. This flaw could potentially result in system compromise via the overwriting of critical system files. The highest threat from this flaw is to users that make use of untrusted third-party repositories.
CVSS Details
- CVSS 3.1 Base Score: 8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade librepo-debuginfoUpgrade librepoUpgrade python-librepoUpgrade librepo-devel | Dec 10, 2020 | Aug 30, 2020 |
| Centos_linux | — | Upgrade librepoUpgrade python-librepoUpgrade librepo-debuginfoUpgrade librepo-develUpgrade librepo-debugsourceUpgrade python3-librepo-debuginfoUpgrade python3-librepo | Sep 9, 2020 | Aug 30, 2020 |
| Huawei Euleros 2_0_sp8 | — | Upgrade librepoUpgrade python3-librepoUpgrade python2-librepo | Nov 26, 2020 | Aug 30, 2020 |
| Huawei Euleros 2_0_sp9 | — | Upgrade librepoUpgrade python3-librepo | Nov 3, 2020 | Aug 30, 2020 |
| Oracle_linux | — | Upgrade python3-librepoUpgrade librepo-develUpgrade librepoUpgrade python-librepo | Sep 10, 2020 | Aug 13, 2020 |
| Redhat Openshift | — | Upgrade redhat-coreos | Dec 29, 2020 | Aug 30, 2020 |
| Redhat_linux | — | Upgrade librepoUpgrade librepo-debugsourceUpgrade python3-librepoUpgrade python3-librepo-debuginfoUpgrade librepo-debuginfoUpgrade python-librepoUpgrade librepo-devel | Sep 9, 2020 | Aug 30, 2020 |
| Suse | — | Upgrade python3-librepoUpgrade librepo-develUpgrade librepo0 | Aug 31, 2020 | Aug 30, 2020 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Aug 30, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub