Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2017-7500

Опубликовано: 13 авг. 2018
Источник: ubuntu
Приоритет: low
CVSS2: 7.2
CVSS3: 7.3

Описание

It was found that rpm did not properly handle RPM installations when a destination path was a symbolic link to a directory, possibly changing ownership and permissions of an arbitrary directory, and RPM files being placed in an arbitrary destination. An attacker, with write access to a directory in which a subdirectory will be installed, could redirect that directory to an arbitrary location and gain root privilege.

РелизСтатусПримечание
artful

ignored

end of life
bionic

not-affected

4.14.1+dfsg1-2
cosmic

ignored

end of life
devel

not-affected

4.16.1.2+dfsg1-0.6
disco

ignored

end of life
eoan

ignored

end of life
esm-apps/bionic

not-affected

4.14.1+dfsg1-2
esm-apps/focal

not-affected

4.14.2.1+dfsg1-1build2
esm-apps/jammy

not-affected

4.16.1.2+dfsg1-0.6
esm-apps/noble

not-affected

4.16.1.2+dfsg1-0.6

Показывать по

7.2 High

CVSS2

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 7.3
redhat
больше 8 лет назад

It was found that rpm did not properly handle RPM installations when a destination path was a symbolic link to a directory, possibly changing ownership and permissions of an arbitrary directory, and RPM files being placed in an arbitrary destination. An attacker, with write access to a directory in which a subdirectory will be installed, could redirect that directory to an arbitrary location and gain root privilege.

CVSS3: 7.3
nvd
больше 7 лет назад

It was found that rpm did not properly handle RPM installations when a destination path was a symbolic link to a directory, possibly changing ownership and permissions of an arbitrary directory, and RPM files being placed in an arbitrary destination. An attacker, with write access to a directory in which a subdirectory will be installed, could redirect that directory to an arbitrary location and gain root privilege.

CVSS3: 7.3
debian
больше 7 лет назад

It was found that rpm did not properly handle RPM installations when a ...

suse-cvrf
больше 7 лет назад

Security update for rpm

suse-cvrf
больше 7 лет назад

Security update for rpm

7.2 High

CVSS2

7.3 High

CVSS3