PT-2017-17793 · Red Hat · Instack-Undercloud
Matthew Booth
+1
·
Published
2017-09-21
·
Updated
2023-02-12
·
CVE-2017-7549
CVSS v3.1
6.4
Medium
| Vector | AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
instack-undercloud versions 5.3.0 through 7.2.0
Description
A flaw was found in instack-undercloud where pre-install and security policy scripts used insecure temporary files. This could allow a local user to conduct a symbolic-link attack, enabling them to overwrite the contents of arbitrary files.
Recommendations
For instack-undercloud version 5.3.0, consider restricting access to temporary files used by pre-install and security policy scripts until a patch is available.
For instack-undercloud version 6.1.0, restrict access to temporary files used by pre-install and security policy scripts until a patch is available.
For instack-undercloud version 7.2.0, restrict access to temporary files used by pre-install and security policy scripts until a patch is available.
Fix
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Instack-Undercloud