CVE-2019-18837: High severity con0217 project con0217 vulnerability
Published Nov 13, 2019
·Updated
An issue was discovered in crun before 0.10.5. With a crafted image, it doesn't correctly check whether a target is a symlink, resulting in access to files outside of the container. This occurs in libcrun/linux.c and libcrun/chrootrealpath.c.
Affected Software
3 affected components
Crun Project Crun<0.10.5
Fedoraproject Fedora=30
Fedoraproject Fedora=31
Remediation
Patch Available
Event History
Nov 13, 2019
CVE Published
via MITRE·08:01 PM
Data Sourced
via MITRE·08:01 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2019-18837.
2
What is the severity of CVE-2019-18837?
The severity of CVE-2019-18837 is high with a CVSS score of 8.6.
3
Which software versions are affected by CVE-2019-18837?
Versions of crun up to and exclusive of 0.10.5 are affected by CVE-2019-18837. Fedora versions 30 and 31 are also affected.
4
How can this vulnerability be exploited?
This vulnerability can be exploited by using a crafted image to gain access to files outside of the container.
5
How can I fix CVE-2019-18837?
To fix CVE-2019-18837, upgrade to version 0.10.5 or later of crun. If you are using Fedora, please update to the latest available version.