Lucene search

K
cveLarry_cashdollarCVE-2016-7490
HistoryNov 10, 2016 - 4:59 p.m.

CVE-2016-7490

2016-11-1016:59:04
CWE-264
CWE-59
larry_cashdollar
web.nvd.nist.gov
25
cve-2016-7490
teradata studio express
file creation
security vulnerability
symlink
privilege escalation

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.5

Confidence

High

EPSS

0

Percentile

5.1%

The installation script studioexpressinstall for Teradata Studio Express 15.12.00.00 creates files in /tmp insecurely. A malicious local user could create a symlink in /tmp and possibly clobber system files or perhaps elevate privileges.

Affected configurations

Nvd
Node
teradatastudio_expressMatch15.12.00.00
VendorProductVersionCPE
teradatastudio_express15.12.00.00cpe:2.3:a:teradata:studio_express:15.12.00.00:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Studio Express",
    "vendor": "Teradata",
    "versions": [
      {
        "status": "affected",
        "version": "15.12.00.00"
      }
    ]
  }
]

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.5

Confidence

High

EPSS

0

Percentile

5.1%

Related for CVE-2016-7490