CVE-2017-7549

A flaw was found in instack-undercloud 7.2.0 as packaged in Red Hat OpenStack Platform Pike, 6.1.0 as packaged in Red Hat OpenStack Platform Oacta, 5.3.0 as packaged in Red Hat OpenStack Newton, where pre-install and security policy scripts used insecure temporary files. A local user could exploit this flaw to conduct a symbolic-link attack, allowing them to overwrite the contents of arbitrary files.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:openstack:instack-undercloud:7.2.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openstack:12:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:a:openstack:instack-undercloud:6.1.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openstack:11:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:a:openstack:instack-undercloud:5.3.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openstack:10:*:*:*:*:*:*:*

History

21 Nov 2024, 03:32

Type Values Removed Values Added
References () http://www.securityfocus.com/bid/100407 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/100407 - Third Party Advisory, VDB Entry
References () https://access.redhat.com/errata/RHSA-2017:2557 - () https://access.redhat.com/errata/RHSA-2017:2557 -
References () https://access.redhat.com/errata/RHSA-2017:2649 - () https://access.redhat.com/errata/RHSA-2017:2649 -
References () https://access.redhat.com/errata/RHSA-2017:2687 - () https://access.redhat.com/errata/RHSA-2017:2687 -
References () https://access.redhat.com/errata/RHSA-2017:2693 - () https://access.redhat.com/errata/RHSA-2017:2693 -
References () https://access.redhat.com/errata/RHSA-2017:2726 - () https://access.redhat.com/errata/RHSA-2017:2726 -
References () https://bugzilla.redhat.com/show_bug.cgi?id=1477403 - Issue Tracking, Vendor Advisory () https://bugzilla.redhat.com/show_bug.cgi?id=1477403 - Issue Tracking, Vendor Advisory

Information

Published : 2017-09-21 21:29

Updated : 2024-11-21 03:32


NVD link : CVE-2017-7549

Mitre link : CVE-2017-7549

CVE.ORG link : CVE-2017-7549


JSON object : View

Products Affected

openstack

  • instack-undercloud

redhat

  • openstack
CWE
CWE-377

Insecure Temporary File

CWE-59

Improper Link Resolution Before File Access ('Link Following')