Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.882934
Category:CentOS Local Security Checks
Title:CentOS Update for yum-NetworkManager-dispatcher CESA-2018:2285 centos7
Summary:Check the version of yum-NetworkManager-dispatcher
Description:Summary:
Check the version of yum-NetworkManager-dispatcher

Vulnerability Insight:
The yum-utils packages provide a collection of utilities and examples for
the yum package manager to make yum easier and more powerful to use.

Security Fix(es):

* yum-utils: reposync: improper path validation may lead to directory
traversal (CVE-2018-10897)

For more details about the security issue(s), including the impact, a CVSS
score, and other related information, refer to the CVE page(s) listed in
the References section.

Red Hat would like to thank Jay Grizzard (Clover Network) and Aaron Levy
(Clover Network) for reporting this issue.

Affected Software/OS:
yum-NetworkManager-dispatcher on CentOS 7

Solution:
Please install the updated packages.

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2018-10897
1041594
http://www.securitytracker.com/id/1041594
RHSA-2018:2284
https://access.redhat.com/errata/RHSA-2018:2284
RHSA-2018:2285
https://access.redhat.com/errata/RHSA-2018:2285
RHSA-2018:2626
https://access.redhat.com/errata/RHSA-2018:2626
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10897
https://github.com/rpm-software-management/yum-utils/commit/6a8de061f8fdc885e74ebe8c94625bf53643b71c
https://github.com/rpm-software-management/yum-utils/commit/7554c0133eb830a71dc01846037cc047d0acbc2c
https://github.com/rpm-software-management/yum-utils/pull/43
https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0
CopyrightCopyright (C) 2018 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.