PT-2017-17793 · Red Hat · Instack-Undercloud

Matthew Booth

+1

·

Published

2017-09-21

·

Updated

2023-02-12

·

CVE-2017-7549

CVSS v3.1

6.4

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions instack-undercloud versions 5.3.0 through 7.2.0
Description A flaw was found in instack-undercloud where pre-install and security policy scripts used insecure temporary files. This could allow a local user to conduct a symbolic-link attack, enabling them to overwrite the contents of arbitrary files.
Recommendations For instack-undercloud version 5.3.0, consider restricting access to temporary files used by pre-install and security policy scripts until a patch is available. For instack-undercloud version 6.1.0, restrict access to temporary files used by pre-install and security policy scripts until a patch is available. For instack-undercloud version 7.2.0, restrict access to temporary files used by pre-install and security policy scripts until a patch is available.

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-7549
GHSA-53WM-97P6-582F
PYSEC-2017-152
RHSA-2017:2557
RHSA-2017:2649
RHSA-2017:2687
RHSA-2017:2693
RHSA-2017:2726

Affected Products

Instack-Undercloud