Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-10870

Опубликовано: 18 июл. 2018
Источник: redhat
CVSS3: 9.8

Описание

redhat-certification does not properly sanitize paths in rhcertStore.py:__saveResultsFile. A remote attacker could use this flaw to overwrite any file, potentially gaining remote code execution.

It has been discovered that redhat-certification does not properly sanitize paths in rhcertStore.py:__saveResultsFile. A remote attacker could use this flaw to overwrite any file, potentially gaining remote code execution.

Меры по смягчению последствий

If SELinux is enabled it further restricts the set of files an attacker may write to. This prevents some basic attacks that would allow to gain remote code execution, though it is not excluded other means are possible.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Certification for Red Hat Enterprise Linux 6redhat-certificationNot affected
Red Hat Certification for Red Hat Enterprise Linux 7redhat-certificationFixedRHSA-2018:237309.08.2018
Red Hat Certification for Red Hat Enterprise Linux 7redhat-certification-hardwareFixedRHSA-2018:237309.08.2018
Red Hat Certification for Red Hat Enterprise Linux 7redhat-certification-hardware-previewFixedRHSA-2018:237309.08.2018

Показывать по

Дополнительная информация

Статус:

Critical
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=1593803redhat-certification: rhcertStore.py: __saveResultsFile allows to write any file

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
больше 7 лет назад

redhat-certification does not properly sanitize paths in rhcertStore.py:__saveResultsFile. A remote attacker could use this flaw to overwrite any file, potentially gaining remote code execution.

CVSS3: 9.8
github
больше 3 лет назад

redhat-certification does not properly sanitize paths in rhcertStore.py:__saveResultsFile. A remote attacker could use this flaw to overwrite any file, potentially gaining remote code execution.

9.8 Critical

CVSS3

Уязвимость CVE-2018-10870