U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2018-10897

Change History

CVE Modified by Red Hat, Inc. 2/02/2023 4:18:06 PM

Action Type Old Value New Value
Removed CWE
Red Hat, Inc. CWE-59

								
						
Removed CWE Reason
CWE-59 / Assessment performed prior to CVMAP efforts

								
						
Changed Description
A directory traversal issue was found in reposync, a part of yum-utils, where reposync fails to sanitize paths in remote repository configuration files. If an attacker controls a repository, they may be able to copy files outside of the destination directory on the targeted system via path traversal. If reposync is running with heightened privileges on a targeted system, this flaw could potentially result in system compromise via the overwriting of critical system files. Version 1.1.31 and older are believed to be affected.
A directory traversal issue was found in reposync, a part of yum-utils, where reposync fails to sanitize paths in remote repository configuration files. If an attacker controls a repository, they may be able to copy files outside of the destination directory on the targeted system via path traversal. If reposync is running with heightened privileges on a targeted system, this flaw could potentially result in system compromise via the overwriting of critical system files.
Added Reference

								
							
							
						
https://access.redhat.com/security/cve/CVE-2018-10897 [No Types Assigned]
Added Reference

								
							
							
						
https://bugzilla.redhat.com/show_bug.cgi?id=1600221 [No Types Assigned]