MGASA-2020-0429

Source
https://advisories.mageia.org/MGASA-2020-0429.html
Import Source
https://advisories.mageia.org/MGASA-2020-0429.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2020-0429
Related
Published
2020-11-21T12:21:00Z
Modified
2020-11-21T11:45:54Z
Summary
Updated librepo packages fix a security vulnerability
Details

It was discovered that librepo was subject to a directory traversal vulnerability where it failed to sanitize paths in remote repository metadata. An attacker controlling a remote repository may be able to copy files outside of the destination directory on the targeted system via path traversal. This flaw could potentially result in system compromise via the overwriting of critical system files (CVE-2020-14352).

References
Credits

Affected packages

Mageia:7 / librepo

Package

Name
librepo
Purl
pkg:rpm/mageia/librepo?arch=source&distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.10.3-1.1.mga7

Ecosystem specific

{
    "section": "core"
}