CVE-2017-7549

A flaw was found in instack-undercloud 7.2.0 as packaged in Red Hat OpenStack Platform Pike, 6.1.0 as packaged in Red Hat OpenStack Platform Oacta, 5.3.0 as packaged in Red Hat OpenStack Newton, where pre-install and security policy scripts used insecure temporary files. A local user could exploit this flaw to conduct a symbolic-link attack, allowing them to overwrite the contents of arbitrary files.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:openstack:instack-undercloud:7.2.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openstack:12:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:a:openstack:instack-undercloud:6.1.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openstack:11:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:a:openstack:instack-undercloud:5.3.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openstack:10:*:*:*:*:*:*:*

Information

Published : 2017-09-21 14:29

Updated : 2023-02-12 15:31


NVD link : CVE-2017-7549

Mitre link : CVE-2017-7549


JSON object : View

CWE
CWE-377

Insecure Temporary File

Advertisement

dedicated server usa

Products Affected

openstack

  • instack-undercloud

redhat

  • openstack