PT-2017-17793 · Red Hat · Instack-Undercloud

Matthew Booth

+1

·

Publicado

2017-09-21

·

Atualizado

2023-02-12

·

CVE-2017-7549

CVSS v3.1

6.4

Média

VetorAV:L/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions instack-undercloud versions 5.3.0 through 7.2.0
Description A flaw was found in instack-undercloud where pre-install and security policy scripts used insecure temporary files. This could allow a local user to conduct a symbolic-link attack, enabling them to overwrite the contents of arbitrary files.
Recommendations For instack-undercloud version 5.3.0, consider restricting access to temporary files used by pre-install and security policy scripts until a patch is available. For instack-undercloud version 6.1.0, restrict access to temporary files used by pre-install and security policy scripts until a patch is available. For instack-undercloud version 7.2.0, restrict access to temporary files used by pre-install and security policy scripts until a patch is available.

Correção

Link Following

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-7549
GHSA-53WM-97P6-582F
PYSEC-2017-152
RHSA-2017:2557
RHSA-2017:2649
RHSA-2017:2687
RHSA-2017:2693
RHSA-2017:2726

Produtos afetados

Instack-Undercloud