CVE-2017-7549

A flaw was found in instack-undercloud 7.2.0 as packaged in Red Hat OpenStack Platform Pike, 6.1.0 as packaged in Red Hat OpenStack Platform Oacta, 5.3.0 as packaged in Red Hat OpenStack Newton, where pre-install and security policy scripts used insecure temporary files. A local user could exploit this flaw to conduct a symbolic-link attack, allowing them to overwrite the contents of arbitrary files.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:openstack:instack-undercloud:7.2.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openstack:12:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:a:openstack:instack-undercloud:6.1.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openstack:11:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:a:openstack:instack-undercloud:5.3.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openstack:10:*:*:*:*:*:*:*

History

No history.

Information

Published : 2017-09-21 21:29

Updated : 2024-02-28 16:04


NVD link : CVE-2017-7549

Mitre link : CVE-2017-7549

CVE.ORG link : CVE-2017-7549


JSON object : View

Products Affected

redhat

  • openstack

openstack

  • instack-undercloud
CWE
CWE-377

Insecure Temporary File

CWE-59

Improper Link Resolution Before File Access ('Link Following')