CVE Vulnerabilities

CVE-2017-7549

Insecure Temporary File

Published: Sep 21, 2017 | Modified: Apr 20, 2025
CVSS 3.x
6.4
MEDIUM
Source:
NVD
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N
CVSS 2.x
3.3 LOW
AV:L/AC:M/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
6.1 MODERATE
CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:L/A:N
Ubuntu
root.io logo minimus.io logo echo.ai logo

A flaw was found in instack-undercloud 7.2.0 as packaged in Red Hat OpenStack Platform Pike, 6.1.0 as packaged in Red Hat OpenStack Platform Oacta, 5.3.0 as packaged in Red Hat OpenStack Newton, where pre-install and security policy scripts used insecure temporary files. A local user could exploit this flaw to conduct a symbolic-link attack, allowing them to overwrite the contents of arbitrary files.

Weakness

Creating and using insecure temporary files can leave application and system data vulnerable to attack.

Affected Software

NameVendorStart VersionEnd Version
Instack-undercloudOpenstack7.2.0 (including)7.2.0 (including)
Red Hat Enterprise Linux OpenStack Platform director 7.0 for RHEL 7RedHatinstack-undercloud-0:2.1.2-41.el7ost*
Red Hat OpenStack Platform 10.0 (Newton)RedHatinstack-undercloud-0:5.3.0-3.el7ost*
Red Hat OpenStack Platform 11.0 (Ocata)RedHatinstack-undercloud-0:6.1.0-3.el7ost*
Red Hat OpenStack Platform 8.0 (Liberty) directorRedHatinstack-undercloud-0:2.2.7-10.el7ost*
Red Hat OpenStack Platform 9.0 (Mitaka) directorRedHatinstack-undercloud-0:4.0.0-17.el7ost*

References