Link Following Affecting buildah package, versions <0:1.9.0-5.module+el8.1.0+4240+893c1ab8
Threat Intelligence
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-CENTOS8-BUILDAH-2019345
- published 26 Jul 2021
- disclosed 22 Aug 2019
Introduced: 22 Aug 2019
CVE-2019-18466 Open this link in a new tabHow to fix?
Upgrade Centos:8
buildah
to version 0:1.9.0-5.module+el8.1.0+4240+893c1ab8 or higher.
NVD Description
Note: Versions mentioned in the description apply only to the upstream buildah
package and not the buildah
package as distributed by Centos
.
See How to fix?
for Centos:8
relevant fixed versions and status.
An issue was discovered in Podman in libpod before 1.6.0. It resolves a symlink in the host context during a copy operation from the container to the host, because an undesired glob operation occurs. An attacker could create a container image containing particular symlinks that, when copied by a victim user to the host filesystem, may overwrite existing files with others from the host.
References
- https://access.redhat.com/security/cve/CVE-2019-18466
- https://bugzilla.redhat.com/show_bug.cgi?id=1744588
- https://github.com/containers/libpod/commit/5c09c4d2947a759724f9d5aef6bac04317e03f7e
- https://github.com/containers/libpod/compare/v1.5.1...v1.6.0
- https://github.com/containers/libpod/issues/3829
- https://access.redhat.com/errata/RHSA-2019:4269
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00040.html