Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:36825
HistoryAug 29, 2022 - 4:37 a.m.

Privilege Escalation

2022-08-2904:37:38
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
30
vulnerability
privilege escalation
symlink
sanitizations
root privileges
cve-2017-7500
cve-2017-7501

EPSS

0.001

Percentile

32.1%

librpm.so is vulnerable to privilege escalation. A local unauthenticated user who owns another ancestor directory is able to potentially gain root privileges of the system due to the lack of sanitizations in lib/fsm.c during symlink validations. This vulnerability exists due to incomplete fixes for CVE-2017-7500 and CVE-2017-7501.