CVE-2020-14352: Path Traversal
A flaw was found in librepo in versions before 1.12.1. A directory traversal vulnerability was found where it failed to sanitize paths in remote repository metadata. An attacker controlling a remote repository may be able to copy files outside of the destination directory on the targeted system via path traversal. This flaw could potentially result in system compromise via the overwriting of critical system files. The highest threat from this flaw is to users that make use of untrusted third-party repositories.
Other sources
Librepo fails to sanitize paths in the 'repomd.xml' configuration file. Malformed or malicious repository metadata could allow a remote attacker to copy files outside of the destination directory via path traversal. Considering that DNF runs as root, this flaw could potentially result in system compromise via arbitrary file overwriting of critical system files.
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-14352?
CVE-2020-14352 is a directory traversal vulnerability found in librepo before version 1.12.1.
How does CVE-2020-14352 affect the affected software?
CVE-2020-14352 affects the librepo package before version 1.12.1.
What is the severity of CVE-2020-14352?
CVE-2020-14352 has a severity level of high, with a severity value of 8.
How can CVE-2020-14352 be fixed?
To fix CVE-2020-14352, update the librepo package to version 1.12.1 or later.
Where can I find more information about CVE-2020-14352?
You can find more information about CVE-2020-14352 in the references: http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00072.html, http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00055.html, https://bugzilla.redhat.com/show_bug.cgi?id=1866498