The Vigil@nce team watches public vulnerabilities impacting your computers, and then offers security solutions, a database and tools to fix them.

Vulnerability of podman: file reading via Symlink

Synthesis of the vulnerability

A local attacker can read a file via Symlink of podman, in order to obtain sensitive information.
Severity of this threat: 2/4.
Creation date: 12/06/2019.
Références of this weakness: CVE-2019-10152, FEDORA-2019-0937bbf558, FEDORA-2019-886b4d2fb6, FEDORA-2019-b66d704846, openSUSE-SU-2019:2044-1, RHSA-2019:1907-01, SUSE-SU-2019:2223-1, VIGILANCE-VUL-29516.

Description of the vulnerability

A local attacker can read a file via Symlink of podman, in order to obtain sensitive information.
Full Vigil@nce bulletin... (Free trial)

This security bulletin impacts software or systems such as Fedora, openSUSE Leap, RHEL, SLES.

Our Vigil@nce team determined that the severity of this cybersecurity announce is medium.

The trust level is of type confirmed by the editor, with an origin of user shell.

An attacker with a expert ability can exploit this vulnerability alert.

Solutions for this threat

Fedora: new podman packages.
New packages are available:
  Fedora 29: podman 1.4.0-2.fc29
  Fedora 30: podman 1.4.0-2.fc30

openSUSE Leap 15.1: new podman packages.
New packages are available:
  openSUSE Leap 15.1: podman 1.4.4-lp151.3.3.1

RHEL 7: new podman packages.
New packages are available:
  RHEL 7: podman 1.4.4-2.el7

SUSE LE 15 SP1: new podman packages.
New packages are available:
  SUSE LE 15 SP1: podman 1.4.4-4.8.1
Full Vigil@nce bulletin... (Free trial)

Computer vulnerabilities tracking service

Vigil@nce provides a computer vulnerability database and alert. The Vigil@nce team tracks computer vulnerabilities impacting systems and applications.