CVE-2017-7500
Severity CVSS v4.0:
Pending analysis
Type:
CWE-59
Link Following
Publication date:
13/08/2018
Last modified:
09/10/2019
Description
It was found that rpm did not properly handle RPM installations when a destination path was a symbolic link to a directory, possibly changing ownership and permissions of an arbitrary directory, and RPM files being placed in an arbitrary destination. An attacker, with write access to a directory in which a subdirectory will be installed, could redirect that directory to an arbitrary location and gain root privilege.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
Base Score 2.0
7.20
Severity 2.0
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:rpm:rpm:*:*:*:*:*:*:*:* | 4.13.0.0 (including) | 4.13.0.2 (excluding) |
cpe:2.3:a:rpm:rpm:4.14.0.0:rc1:*:*:*:*:*:* | ||
cpe:2.3:a:rpm:rpm:4.14.0.0:rc2:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page