CVE-2019-18466

An issue was discovered in Podman in libpod before 1.6.0. It resolves a symlink in the host context during a copy operation from the container to the host, because an undesired glob operation occurs. An attacker could create a container image containing particular symlinks that, when copied by a victim user to the host filesystem, may overwrite existing files with others from the host.
Link Following
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.5 MEDIUM
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 75%
Affected Products (NVD)
VendorProductVersion
libpod_projectlibpod
𝑥
< 1.6.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libpod
bookworm
4.3.1+ds1-8+deb12u1
fixed
bullseye
3.0.1+dfsg1-3+deb11u5
fixed
sid
5.2.2+ds1-2
fixed
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
cni
suse enterprise sap 15 SP1
0.7.1-3.3.1
fixed
suse enterprise sap 15 SP2
0.7.1-3.3.1
fixed
suse enterprise sap 15 SP3
0.7.1-3.3.1
fixed
suse enterprise sap 15 SP4
0.7.1-3.3.1
fixed
suse enterprise server 15 SP1
0.7.1-3.3.1
fixed
suse enterprise server 15 SP2
0.7.1-3.3.1
fixed
suse enterprise server 15 SP3
0.7.1-3.3.1
fixed
suse enterprise server 15 SP4
0.7.1-3.3.1
fixed
cni-plugins
suse enterprise sap 15 SP1
0.8.4-3.3.1
fixed
suse enterprise sap 15 SP2
0.8.4-3.3.1
fixed
suse enterprise sap 15 SP3
0.8.4-3.3.1
fixed
suse enterprise sap 15 SP4
0.8.4-3.3.1
fixed
suse enterprise server 15 SP1
0.8.4-3.3.1
fixed
suse enterprise server 15 SP2
0.8.4-3.3.1
fixed
suse enterprise server 15 SP3
0.8.4-3.3.1
fixed
suse enterprise server 15 SP4
0.8.4-3.3.1
fixed
conmon
suse enterprise sap 15 SP1
2.0.10-3.3.1
fixed
suse enterprise sap 15 SP2
2.0.10-3.3.1
fixed
suse enterprise sap 15 SP3
2.0.10-3.3.1
fixed
suse enterprise server 15 SP1
2.0.10-3.3.1
fixed
suse enterprise server 15 SP2
2.0.10-3.3.1
fixed
suse enterprise server 15 SP3
2.0.10-3.3.1
fixed
fuse-overlayfs
suse enterprise sap 15 SP1
0.7.6-3.6.1
fixed
suse enterprise sap 15 SP2
0.7.6-3.6.1
fixed
suse enterprise sap 15 SP3
0.7.6-3.6.1
fixed
suse enterprise sap 15 SP4
0.7.6-3.6.1
fixed
suse enterprise server 15 SP1
0.7.6-3.6.1
fixed
suse enterprise server 15 SP2
0.7.6-3.6.1
fixed
suse enterprise server 15 SP3
0.7.6-3.6.1
fixed
suse enterprise server 15 SP4
0.7.6-3.6.1
fixed
podman
suse enterprise sap 15 SP1
1.8.0-4.14.1
fixed
suse enterprise sap 15 SP2
1.8.0-4.14.1
fixed
suse enterprise sap 15 SP3
1.8.0-4.14.1
fixed
suse enterprise server 15 SP1
1.8.0-4.14.1
fixed
suse enterprise server 15 SP2
1.8.0-4.14.1
fixed
suse enterprise server 15 SP3
1.8.0-4.14.1
fixed
podman-cni-config
suse enterprise sap 15 SP1
1.8.0-4.14.1
fixed
suse enterprise sap 15 SP2
1.8.0-4.14.1
fixed
suse enterprise sap 15 SP3
1.8.0-4.14.1
fixed
suse enterprise server 15 SP1
1.8.0-4.14.1
fixed
suse enterprise server 15 SP2
1.8.0-4.14.1
fixed
suse enterprise server 15 SP3
1.8.0-4.14.1
fixed