Description
An issue was discovered in Podman in libpod before 1.6.0. It resolves a symlink in the host context during a copy operation from the container to the host, because an undesired glob operation occurs. An attacker could create a container image containing particular symlinks that, when copied by a victim user to the host filesystem, may overwrite existing files with others from the host.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-5078 | An issue was discovered in Podman in libpod before 1.6.0. It resolves a symlink in the host context during a copy operation from the container to the host, because an undesired glob operation occurs. An attacker could create a container image containing particular symlinks that, when copied by a victim user to the host filesystem, may overwrite existing files with others from the host. |
Github GHSA |
GHSA-r34v-gqmw-qvgj | Podman Symlink Vulnerability |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T01:54:14.351Z
Reserved: 2019-10-28T00:00:00.000Z
Link: CVE-2019-18466
No data.
Status : Modified
Published: 2019-10-28T13:15:11.430
Modified: 2024-11-21T04:33:17.487
Link: CVE-2019-18466
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA