CVE-2019-9686: Path Traversal
pacman before 5.1.3 allows directory traversal when installing a remote package via a specified URL "pacman -U <url>" due to an unsanitized file name received from a Content-Disposition header. pacman renames the downloaded package file to match the name given in this header. However, pacman did not sanitize this name, which may contain slashes, before calling rename(). A malicious server (or a network MitM if downloading over HTTP) can send a Content-Disposition header to make pacman place the file anywhere in the filesystem, potentially leading to arbitrary root code execution. Notably, this bypasses pacman's package signature checking. This occurs in curldownloadinternal in lib/libalpm/dload.c.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-9686?
CVE-2019-9686 is rated as a medium severity vulnerability due to its potential for directory traversal exploits.
How do I fix CVE-2019-9686?
To fix CVE-2019-9686, upgrade to pacman version 5.1.3 or later.
What software is affected by CVE-2019-9686?
CVE-2019-9686 affects pacman versions before 5.1.3.
What type of vulnerability is CVE-2019-9686?
CVE-2019-9686 is a directory traversal vulnerability that can be exploited during remote package installations.
Can CVE-2019-9686 be exploited remotely?
Yes, CVE-2019-9686 can be exploited remotely when installing packages via a specified URL.