CVE-2018-10897

A directory traversal issue was found in reposync, a part of yum-utils, where reposync fails to sanitize paths in remote repository configuration files. If an attacker controls a repository, they may be able to copy files outside of the destination directory on the targeted system via path traversal. If reposync is running with heightened privileges on a targeted system, this flaw could potentially result in system compromise via the overwriting of critical system files. Version 1.1.31 and older are believed to be affected.
Link Following
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.1 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 85%
Affected Products (NVD)
VendorProductVersion
rpmyum-utils
𝑥
≤ 1.1.31
redhatvirtualization
4.0
redhatenterprise_linux_desktop
6.0
redhatenterprise_linux_desktop
7.0
redhatenterprise_linux_server
6.0
redhatenterprise_linux_server
7.0
redhatenterprise_linux_workstation
6.0
redhatenterprise_linux_workstation
7.0
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
yum-utils
artful
ignored
bionic
not-affected
cosmic
ignored
disco
not-affected
trusty
dne
xenial
not-affected
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
yum-NetworkManager-dispatcher
RHEL 6
0:1.1.30-42.el6_10
fixed
RHEL 7
0:1.1.31-46.el7_5
fixed
yum-plugin-aliases
RHEL 6
0:1.1.30-42.el6_10
fixed
RHEL 7
0:1.1.31-46.el7_5
fixed
yum-plugin-auto-update-debug-info
RHEL 6
0:1.1.30-42.el6_10
fixed
RHEL 7
0:1.1.31-46.el7_5
fixed
yum-plugin-changelog
RHEL 6
0:1.1.30-42.el6_10
fixed
RHEL 7
0:1.1.31-46.el7_5
fixed
yum-plugin-copr
RHEL 7
0:1.1.31-46.el7_5
fixed
yum-plugin-fastestmirror
RHEL 6
0:1.1.30-42.el6_10
fixed
RHEL 7
0:1.1.31-46.el7_5
fixed
yum-plugin-filter-data
RHEL 6
0:1.1.30-42.el6_10
fixed
RHEL 7
0:1.1.31-46.el7_5
fixed
yum-plugin-fs-snapshot
RHEL 6
0:1.1.30-42.el6_10
fixed
RHEL 7
0:1.1.31-46.el7_5
fixed
yum-plugin-keys
RHEL 6
0:1.1.30-42.el6_10
fixed
RHEL 7
0:1.1.31-46.el7_5
fixed
yum-plugin-list-data
RHEL 6
0:1.1.30-42.el6_10
fixed
RHEL 7
0:1.1.31-46.el7_5
fixed
yum-plugin-local
RHEL 6
0:1.1.30-42.el6_10
fixed
RHEL 7
0:1.1.31-46.el7_5
fixed
yum-plugin-merge-conf
RHEL 6
0:1.1.30-42.el6_10
fixed
RHEL 7
0:1.1.31-46.el7_5
fixed
yum-plugin-ovl
RHEL 6
0:1.1.30-42.el6_10
fixed
RHEL 7
0:1.1.31-46.el7_5
fixed
yum-plugin-post-transaction-actions
RHEL 6
0:1.1.30-42.el6_10
fixed
RHEL 7
0:1.1.31-46.el7_5
fixed
yum-plugin-pre-transaction-actions
RHEL 7
0:1.1.31-46.el7_5
fixed
yum-plugin-priorities
RHEL 6
0:1.1.30-42.el6_10
fixed
RHEL 7
0:1.1.31-46.el7_5
fixed
yum-plugin-protectbase
RHEL 6
0:1.1.30-42.el6_10
fixed
RHEL 7
0:1.1.31-46.el7_5
fixed
yum-plugin-ps
RHEL 6
0:1.1.30-42.el6_10
fixed
RHEL 7
0:1.1.31-46.el7_5
fixed
yum-plugin-remove-with-leaves
RHEL 6
0:1.1.30-42.el6_10
fixed
RHEL 7
0:1.1.31-46.el7_5
fixed
yum-plugin-rpm-warm-cache
RHEL 6
0:1.1.30-42.el6_10
fixed
RHEL 7
0:1.1.31-46.el7_5
fixed
yum-plugin-security
RHEL 6
0:1.1.30-42.el6_10
fixed
yum-plugin-show-leaves
RHEL 6
0:1.1.30-42.el6_10
fixed
RHEL 7
0:1.1.31-46.el7_5
fixed
yum-plugin-tmprepo
RHEL 6
0:1.1.30-42.el6_10
fixed
RHEL 7
0:1.1.31-46.el7_5
fixed
yum-plugin-tsflags
RHEL 6
0:1.1.30-42.el6_10
fixed
RHEL 7
0:1.1.31-46.el7_5
fixed
yum-plugin-upgrade-helper
RHEL 6
0:1.1.30-42.el6_10
fixed
RHEL 7
0:1.1.31-46.el7_5
fixed
yum-plugin-verify
RHEL 6
0:1.1.30-42.el6_10
fixed
RHEL 7
0:1.1.31-46.el7_5
fixed
yum-plugin-versionlock
RHEL 6
0:1.1.30-42.el6_10
fixed
RHEL 7
0:1.1.31-46.el7_5
fixed
yum-updateonboot
RHEL 6
0:1.1.30-42.el6_10
fixed
RHEL 7
0:1.1.31-46.el7_5
fixed
yum-utils
RHEL 6
0:1.1.30-42.el6_10
fixed
RHEL 7
0:1.1.31-46.el7_5
fixed