You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
See doc/triage.md for instructions on how to triage this report.
modules:
- module: github.com/containers/podman/v4
versions:
- fixed: 1.6.0
packages:
- package: github.com/containers/podman/v4
summary: Podman Symlink Vulnerability
description: |-
An issue was discovered in Podman in libpod before 1.6.0. It resolves a symlink
in the host context during a copy operation from the container to the host,
because an undesired glob operation occurs. An attacker could create a container
image containing particular symlinks that, when copied by a victim user to the
host filesystem, may overwrite existing files with others from the host.
cves:
- CVE-2019-18466
ghsas:
- GHSA-r34v-gqmw-qvgj
references:
- web: https://nvd.nist.gov/vuln/detail/CVE-2019-18466
- report: https://github.com/containers/libpod/issues/3829
- fix: https://github.com/containers/libpod/commit/5c09c4d2947a759724f9d5aef6bac04317e03f7e
- web: https://access.redhat.com/errata/RHSA-2019:4269
- web: https://bugzilla.redhat.com/show_bug.cgi?id=1744588
- web: https://github.com/containers/libpod/compare/v1.5.1...v1.6.0
- advisory: https://github.com/advisories/GHSA-r34v-gqmw-qvgj
The text was updated successfully, but these errors were encountered:
In GitHub Security Advisory GHSA-r34v-gqmw-qvgj, there is a vulnerability in the following Go packages or modules:
Cross references:
See doc/triage.md for instructions on how to triage this report.
The text was updated successfully, but these errors were encountered: