Логотип exploitDog
bind:CVE-2017-7549
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2017-7549

Количество 3

Количество 3

redhat логотип

CVE-2017-7549

больше 8 лет назад

A flaw was found in instack-undercloud 7.2.0 as packaged in Red Hat OpenStack Platform Pike, 6.1.0 as packaged in Red Hat OpenStack Platform Oacta, 5.3.0 as packaged in Red Hat OpenStack Newton, where pre-install and security policy scripts used insecure temporary files. A local user could exploit this flaw to conduct a symbolic-link attack, allowing them to overwrite the contents of arbitrary files.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2017-7549

больше 8 лет назад

A flaw was found in instack-undercloud 7.2.0 as packaged in Red Hat OpenStack Platform Pike, 6.1.0 as packaged in Red Hat OpenStack Platform Oacta, 5.3.0 as packaged in Red Hat OpenStack Newton, where pre-install and security policy scripts used insecure temporary files. A local user could exploit this flaw to conduct a symbolic-link attack, allowing them to overwrite the contents of arbitrary files.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-53wm-97p6-582f

больше 3 лет назад

instack-undercloud vulnerable to symlink attack on tmp files

CVSS3: 6.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2017-7549

A flaw was found in instack-undercloud 7.2.0 as packaged in Red Hat OpenStack Platform Pike, 6.1.0 as packaged in Red Hat OpenStack Platform Oacta, 5.3.0 as packaged in Red Hat OpenStack Newton, where pre-install and security policy scripts used insecure temporary files. A local user could exploit this flaw to conduct a symbolic-link attack, allowing them to overwrite the contents of arbitrary files.

CVSS3: 6.1
0%
Низкий
больше 8 лет назад
nvd логотип
CVE-2017-7549

A flaw was found in instack-undercloud 7.2.0 as packaged in Red Hat OpenStack Platform Pike, 6.1.0 as packaged in Red Hat OpenStack Platform Oacta, 5.3.0 as packaged in Red Hat OpenStack Newton, where pre-install and security policy scripts used insecure temporary files. A local user could exploit this flaw to conduct a symbolic-link attack, allowing them to overwrite the contents of arbitrary files.

CVSS3: 6.4
0%
Низкий
больше 8 лет назад
github логотип
GHSA-53wm-97p6-582f

instack-undercloud vulnerable to symlink attack on tmp files

CVSS3: 6.4
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу