Lucene search

K
prionPRIOn knowledge basePRION:CVE-2017-7500
HistoryAug 13, 2018 - 5:29 p.m.

Design/Logic Flaw

2018-08-1317:29:00
PRIOn knowledge base
www.prio-n.com
7

6.9 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

20.8%

It was found that rpm did not properly handle RPM installations when a destination path was a symbolic link to a directory, possibly changing ownership and permissions of an arbitrary directory, and RPM files being placed in an arbitrary destination. An attacker, with write access to a directory in which a subdirectory will be installed, could redirect that directory to an arbitrary location and gain root privilege.

6.9 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

20.8%