~ubuntu-security/ubuntu-cve-tracker/master

« back to all changes in this revision

Viewing changes to active/CVE-2017-7501

  • Committer: Steve Beattie
  • Date: 2019-02-19 06:18:27 UTC
  • Revision ID: sbeattie@ubuntu.com-20190219061827-oh57fzcfc1u9dlfk
The ubuntu-cve-tracker project has been converted to git.

Please use 'git clone https://git.launchpad.net/ubuntu-cve-tracker' to
get the converted tree.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
Candidate: CVE-2017-7501
2
 
PublicDate: 2017-11-22
3
 
References:
4
 
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7501
5
 
 https://bugzilla.redhat.com/show_bug.cgi?id=1452133
6
 
Description:
7
 
 It was found that versions of rpm before 4.13.0.2 use temporary files with
8
 
 predictable names when installing an RPM. An attacker with ability to write
9
 
 in a directory where files will be installed could create symbolic links to
10
 
 an arbitrary location and modify content, and possibly permissions to
11
 
 arbitrary files, which could be used for denial of service or possibly
12
 
 privilege escalation.
13
 
Ubuntu-Description:
14
 
Notes:
15
 
Bugs:
16
 
Priority: low
17
 
Discovered-by:
18
 
Assigned-to:
19
 
 
20
 
Patches_rpm:
21
 
upstream_rpm: needs-triage
22
 
precise/esm_rpm: needs-triage
23
 
trusty_rpm: needs-triage
24
 
vivid/ubuntu-core_rpm: DNE
25
 
xenial_rpm: needs-triage
26
 
yakkety_rpm: ignored (reached end-of-life)
27
 
zesty_rpm: ignored (reached end-of-life)
28
 
artful_rpm: needs-triage
29
 
bionic_rpm: needs-triage
30
 
devel_rpm: needs-triage