Bugzilla – Bug 1100972
VUL-0: CVE-2018-10897: yum-utils: reposync: improper path validation may lead to directory traversal
Last modified: 2022-04-26 09:38:06 UTC
via rh bugzilla Reposync fails to sanitize paths in remote repository configuration files. If an attacker controls a repository a user is syncing with, the attacker may be able to copy files outside of the destination directory via path traversal. If reposync is running with heightened privileges on a targeted system, this flaw could potentially result in system compromise via the overwriting of critical system files. References: https://bugzilla.redhat.com/show_bug.cgi?id=1600221 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-10897
based on comment #10, back to the Security team.
Done.