CVE Vulnerabilities

CVE-2017-7560

Insecure Temporary File

Published: Sep 13, 2017 | Modified: Nov 21, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
4.9 MEDIUM
AV:L/AC:L/Au:N/C:N/I:N/A:C
RedHat/V2
RedHat/V3
5.5 LOW
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Ubuntu
LOW

It was found that rhnsd PID files are created as world-writable that allows local attackers to fill the disks or to kill selected processes.

Weakness

Creating and using insecure temporary files can leave application and system data vulnerable to attack.

Affected Software

Name Vendor Start Version End Version
Rhnsd Redhat - (including) - (including)
Rhnsd Ubuntu artful *
Rhnsd Ubuntu zesty *

References