CVE-2016-7490: High severity teradata studio express vulnerability
The installation script studioexpressinstall for Teradata Studio Express 15.12.00.00 creates files in /tmp insecurely. A malicious local user could create a symlink in /tmp and possibly clobber system files or perhaps elevate privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-7490?
CVE-2016-7490 is considered a high-severity vulnerability due to its potential for local privilege escalation.
How do I fix CVE-2016-7490?
To fix CVE-2016-7490, it is recommended to update Teradata Studio Express to a version that addresses this insecure temporary file creation issue.
Who is affected by CVE-2016-7490?
Users of Teradata Studio Express version 15.12.00.00 are affected by CVE-2016-7490.
What type of attack can exploit CVE-2016-7490?
CVE-2016-7490 can be exploited through local symlink attacks by a malicious user to overwrite sensitive files or escalate privileges.
Is there a workaround for CVE-2016-7490?
As a temporary workaround for CVE-2016-7490, users should avoid using the affected version and restrict access to the /tmp directory.