CVE-2019-18466 is a vulnerability in Podman (libpod before 1.6.0) where a symlink resolution issue during a container-to-host copy operation can lead to arbitrary file overwrites. An attacker could craft a malicious container image containing specific symlinks, which, when copied by a user, could overwrite existing host files with other host files. Rated as MEDIUM severity (CVSS 5.5), this vulnerability requires user interaction (UI:R) and local access (AV:L) to achieve high integrity impact (I:H). There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.6.0CPE matchmatch criteria | cpe:2.3:a:libpod_project:libpod:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.