GHSA-r34v-gqmw-qvgj

Source
https://github.com/advisories/GHSA-r34v-gqmw-qvgj
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-r34v-gqmw-qvgj/GHSA-r34v-gqmw-qvgj.json
Aliases
Published
2022-05-24T16:59:58Z
Modified
2023-11-08T04:01:25.966011Z
Summary
Podman Symlink Vulnerability
Details

An issue was discovered in Podman in libpod before 1.6.0. It resolves a symlink in the host context during a copy operation from the container to the host, because an undesired glob operation occurs. An attacker could create a container image containing particular symlinks that, when copied by a victim user to the host filesystem, may overwrite existing files with others from the host.

References

Affected packages

Go / github.com/containers/podman/v4

Affected ranges

Type
SEMVER
Events
Introduced
0The exact introduced commit is unknown
Fixed
1.6.0