CVE Vulnerabilities

CVE-2017-7549

Insecure Temporary File

Published: Sep 21, 2017 | Modified: Nov 21, 2024
CVSS 3.x
6.4
MEDIUM
Source:
NVD
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N
CVSS 2.x
3.3 LOW
AV:L/AC:M/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
6.1 MODERATE
CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:L/A:N
Ubuntu

A flaw was found in instack-undercloud 7.2.0 as packaged in Red Hat OpenStack Platform Pike, 6.1.0 as packaged in Red Hat OpenStack Platform Oacta, 5.3.0 as packaged in Red Hat OpenStack Newton, where pre-install and security policy scripts used insecure temporary files. A local user could exploit this flaw to conduct a symbolic-link attack, allowing them to overwrite the contents of arbitrary files.

Weakness

Creating and using insecure temporary files can leave application and system data vulnerable to attack.

Affected Software

Name Vendor Start Version End Version
Instack-undercloud Openstack 7.2.0 (including) 7.2.0 (including)
Red Hat Enterprise Linux OpenStack Platform director 7.0 for RHEL 7 RedHat instack-undercloud-0:2.1.2-41.el7ost *
Red Hat OpenStack Platform 10.0 (Newton) RedHat instack-undercloud-0:5.3.0-3.el7ost *
Red Hat OpenStack Platform 11.0 (Ocata) RedHat instack-undercloud-0:6.1.0-3.el7ost *
Red Hat OpenStack Platform 8.0 (Liberty) director RedHat instack-undercloud-0:2.2.7-10.el7ost *
Red Hat OpenStack Platform 9.0 (Mitaka) director RedHat instack-undercloud-0:4.0.0-17.el7ost *

References