Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2017-7796

Опубликовано: 11 июн. 2018
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 3.3
CVSS3: 4.7

Описание

On Windows systems, the logger run by the Windows updater deletes the file "update.log" before it runs in order to write a new log of that name. The path to this file is supplied at the command line to the updater and could be used in concert with another local exploit to delete a different file named "update.log" instead of the one intended. Note: This attack only affects Windows operating systems. Other operating systems are not affected. This vulnerability affects Firefox < 55.

РелизСтатусПримечание
devel

not-affected

esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was not-affected]
precise/esm

DNE

trusty

not-affected

trusty/esm

DNE

trusty was not-affected
upstream

released

55.0
vivid/ubuntu-core

DNE

xenial

not-affected

zesty

not-affected

Показывать по

Ссылки на источники

EPSS

Процентиль: 18%
0.00057
Низкий

3.3 Low

CVSS2

4.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.7
nvd
около 7 лет назад

On Windows systems, the logger run by the Windows updater deletes the file "update.log" before it runs in order to write a new log of that name. The path to this file is supplied at the command line to the updater and could be used in concert with another local exploit to delete a different file named "update.log" instead of the one intended. Note: This attack only affects Windows operating systems. Other operating systems are not affected. This vulnerability affects Firefox < 55.

CVSS3: 4.7
debian
около 7 лет назад

On Windows systems, the logger run by the Windows updater deletes the ...

CVSS3: 4.7
github
около 3 лет назад

On Windows systems, the logger run by the Windows updater deletes the file "update.log" before it runs in order to write a new log of that name. The path to this file is supplied at the command line to the updater and could be used in concert with another local exploit to delete a different file named "update.log" instead of the one intended. Note: This attack only affects Windows operating systems. Other operating systems are not affected. This vulnerability affects Firefox < 55.

EPSS

Процентиль: 18%
0.00057
Низкий

3.3 Low

CVSS2

4.7 Medium

CVSS3