Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-7501

Опубликовано: 22 нояб. 2017
Источник: debian

Описание

It was found that versions of rpm before 4.13.0.2 use temporary files with predictable names when installing an RPM. An attacker with ability to write in a directory where files will be installed could create symbolic links to an arbitrary location and modify content, and possibly permissions to arbitrary files, which could be used for denial of service or possibly privilege escalation.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
rpmunfixedpackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=1452133

  • Not supported for installations in Debian (and an unprivileged attacker would not have permissions for systems directories anyway)

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 8 лет назад

It was found that versions of rpm before 4.13.0.2 use temporary files with predictable names when installing an RPM. An attacker with ability to write in a directory where files will be installed could create symbolic links to an arbitrary location and modify content, and possibly permissions to arbitrary files, which could be used for denial of service or possibly privilege escalation.

CVSS3: 7.3
redhat
около 9 лет назад

It was found that versions of rpm before 4.13.0.2 use temporary files with predictable names when installing an RPM. An attacker with ability to write in a directory where files will be installed could create symbolic links to an arbitrary location and modify content, and possibly permissions to arbitrary files, which could be used for denial of service or possibly privilege escalation.

CVSS3: 7.8
nvd
больше 8 лет назад

It was found that versions of rpm before 4.13.0.2 use temporary files with predictable names when installing an RPM. An attacker with ability to write in a directory where files will be installed could create symbolic links to an arbitrary location and modify content, and possibly permissions to arbitrary files, which could be used for denial of service or possibly privilege escalation.

CVSS3: 7.8
github
больше 4 лет назад

It was found that versions of rpm before 4.13.0.2 use temporary files with predictable names when installing an RPM. An attacker with ability to write in a directory where files will be installed could create symbolic links to an arbitrary location and modify content, and possibly permissions to arbitrary files, which could be used for denial of service or possibly privilege escalation.

suse-cvrf
почти 8 лет назад

Security update for rpm