SB2019061011 - Fedora 30 update for podman
Published: June 10, 2019 Updated: April 25, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Path traversal (CVE-ID: CVE-2019-10152)
The vulnerability allows a local attacker to perform directory traversal attacks.
The vulnerability exists due to the software does not properly resolve symlinks within containers. A local authenticated attacker who has compromised an existing container can cause arbitrary files on the host filesystem to be read/written when an administrator tries to copy a file from/to the container.
Remediation
Install update from vendor's website.