Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-7500

Опубликовано: 13 авг. 2018
Источник: nvd
CVSS3: 7.3
CVSS3: 7.8
CVSS2: 7.2
EPSS Низкий

Описание

It was found that rpm did not properly handle RPM installations when a destination path was a symbolic link to a directory, possibly changing ownership and permissions of an arbitrary directory, and RPM files being placed in an arbitrary destination. An attacker, with write access to a directory in which a subdirectory will be installed, could redirect that directory to an arbitrary location and gain root privilege.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:rpm:rpm:*:*:*:*:*:*:*:*
Версия от 4.13.0.0 (включая) до 4.13.0.2 (исключая)
cpe:2.3:a:rpm:rpm:4.14.0.0:rc1:*:*:*:*:*:*
cpe:2.3:a:rpm:rpm:4.14.0.0:rc2:*:*:*:*:*:*

EPSS

Процентиль: 17%
0.00054
Низкий

7.3 High

CVSS3

7.8 High

CVSS3

7.2 High

CVSS2

Дефекты

CWE-59
CWE-59

Связанные уязвимости

CVSS3: 7.3
ubuntu
больше 7 лет назад

It was found that rpm did not properly handle RPM installations when a destination path was a symbolic link to a directory, possibly changing ownership and permissions of an arbitrary directory, and RPM files being placed in an arbitrary destination. An attacker, with write access to a directory in which a subdirectory will be installed, could redirect that directory to an arbitrary location and gain root privilege.

CVSS3: 7.3
redhat
больше 8 лет назад

It was found that rpm did not properly handle RPM installations when a destination path was a symbolic link to a directory, possibly changing ownership and permissions of an arbitrary directory, and RPM files being placed in an arbitrary destination. An attacker, with write access to a directory in which a subdirectory will be installed, could redirect that directory to an arbitrary location and gain root privilege.

CVSS3: 7.3
debian
больше 7 лет назад

It was found that rpm did not properly handle RPM installations when a ...

suse-cvrf
больше 7 лет назад

Security update for rpm

suse-cvrf
больше 7 лет назад

Security update for rpm

EPSS

Процентиль: 17%
0.00054
Низкий

7.3 High

CVSS3

7.8 High

CVSS3

7.2 High

CVSS2

Дефекты

CWE-59
CWE-59