Описание
Red Hat Gluster Storage RPM Package 3.2 allows local users to gain privileges and execute arbitrary code as root.
It was found that glusterfs-server RPM package would write file with predictable name into world readable /tmp directory. A local attacker could potentially use this flaw to escalate their privileges to root by modifying the shell script during the installation of the glusterfs-server package.
Отчет
This issue did not affect the versions of glusterfs as shipped with Red Hat Enterprise Linux 6, and 7.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | glusterfs | Not affected | ||
| Red Hat Storage 2.1 | glusterfs | Will not fix | ||
| Native Client for RHEL 6 for Red Hat Storage | glusterfs | Fixed | RHSA-2017:0484 | 23.03.2017 |
| Native Client for RHEL 7 for Red Hat Storage | glusterfs | Fixed | RHSA-2017:0486 | 23.03.2017 |
| Red Hat Gluster Storage 3.2 for RHEL 6 | glusterfs | Fixed | RHSA-2017:0484 | 23.03.2017 |
| Red Hat Gluster Storage 3.2 for RHEL 6 | redhat-storage-server | Fixed | RHSA-2017:0484 | 23.03.2017 |
| Red Hat Gluster Storage 3.2 for RHEL 7 | glusterfs | Fixed | RHSA-2017:0486 | 23.03.2017 |
| Red Hat Gluster Storage 3.2 for RHEL 7 | redhat-storage-server | Fixed | RHSA-2017:0486 | 23.03.2017 |
| Red Hat Gluster Storage 3.2 for RHEL 7 | vdsm | Fixed | RHSA-2017:0486 | 23.03.2017 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | glusterfs | Fixed | RHSA-2017:0486 | 23.03.2017 |
Показывать по
Дополнительная информация
Статус:
EPSS
4.8 Medium
CVSS3
4.4 Medium
CVSS2
Связанные уязвимости
Red Hat Gluster Storage RPM Package 3.2 allows local users to gain privileges and execute arbitrary code as root.
Red Hat Gluster Storage RPM Package 3.2 allows local users to gain privileges and execute arbitrary code as root.
Red Hat Gluster Storage RPM Package 3.2 allows local users to gain pri ...
Red Hat Gluster Storage RPM Package 3.2 allows local users to gain privileges and execute arbitrary code as root.
EPSS
4.8 Medium
CVSS3
4.4 Medium
CVSS2