(1) installer/basedefs.py and (2) modules/ospluginutils.py in PackStack allows local users to overwrite arbitrary files via a symlink attack on a temporary file with a predictable name in /tmp.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Essex | Openstack | - (including) | - (including) |
Folsom | Openstack | - (including) | - (including) |