Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-0778

Опубликовано: 27 мар. 2023
Источник: debian
EPSS Низкий

Описание

A Time-of-check Time-of-use (TOCTOU) flaw was found in podman. This issue may allow a malicious user to replace a normal file in a volume with a symlink while exporting the volume, allowing for access to arbitrary files on the host file system.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libpodfixed4.3.1+ds1-7package
libpodnot-affectedbullseyepackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=2168256

  • Introduced with: https://github.com/containers/podman/commit/edddfe8c4f7761b12dc64ea4aa0a83b755aa124f (v3.4.0-rc1)

  • Fixed by: https://github.com/containers/podman/commit/6ca857feb07a5fdc96fd947afef03916291673d8 (v4.5.0-rc1)

EPSS

Процентиль: 31%
0.00115
Низкий

Связанные уязвимости

CVSS3: 6.8
ubuntu
около 2 лет назад

A Time-of-check Time-of-use (TOCTOU) flaw was found in podman. This issue may allow a malicious user to replace a normal file in a volume with a symlink while exporting the volume, allowing for access to arbitrary files on the host file system.

CVSS3: 6.8
redhat
больше 2 лет назад

A Time-of-check Time-of-use (TOCTOU) flaw was found in podman. This issue may allow a malicious user to replace a normal file in a volume with a symlink while exporting the volume, allowing for access to arbitrary files on the host file system.

CVSS3: 6.8
nvd
около 2 лет назад

A Time-of-check Time-of-use (TOCTOU) flaw was found in podman. This issue may allow a malicious user to replace a normal file in a volume with a symlink while exporting the volume, allowing for access to arbitrary files on the host file system.

suse-cvrf
около 2 лет назад

Security update for podman

suse-cvrf
около 2 лет назад

Security update for podman

EPSS

Процентиль: 31%
0.00115
Низкий