[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248678

 
 

909

 
 

195426

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2020-14352Date: (C)2020-08-31   (M)2023-12-22


A flaw was found in librepo in versions before 1.12.1. A directory traversal vulnerability was found where it failed to sanitize paths in remote repository metadata. An attacker controlling a remote repository may be able to copy files outside of the destination directory on the targeted system via path traversal. This flaw could potentially result in system compromise via the overwriting of critical system files. The highest threat from this flaw is to users that make use of untrusted third-party repositories.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 8.0CVSS Score : 8.5
Exploit Score: 2.1Exploit Score: 6.8
Impact Score: 5.9Impact Score: 10.0
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: NETWORKAccess Vector: NETWORK
Attack Complexity: LOWAccess Complexity: MEDIUM
Privileges Required: LOWAuthentication: SINGLE
User Interaction: REQUIREDConfidentiality: COMPLETE
Scope: UNCHANGEDIntegrity: COMPLETE
Confidentiality: HIGHAvailability: COMPLETE
Integrity: HIGH 
Availability: HIGH 
  
Reference:
FEDORA-2020-5d9f0ce2b3
FEDORA-2020-7906a64449
FEDORA-2020-b40fc174b5
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00072.html
https://bugzilla.redhat.com/show_bug.cgi?id=1866498
openSUSE-SU-2020:1428

CWE    1
CWE-22
OVAL    16
oval:org.secpod.oval:def:505178
oval:org.secpod.oval:def:66571
oval:org.secpod.oval:def:118818
oval:org.secpod.oval:def:118817
...

© SecPod Technologies