CVE-2017-7496: High severity Fedoraproject Arm Installer vulnerability
Published Jun 26, 2017
·Updated
fedora-arm-installer up to and including 1.99.16 is vulnerable to local privilege escalation due to lack of checking the error condition of mount operation failure on unsafely created temporary directories.
Affected Software
1 affected component
Fedoraproject Arm Installer<=1.99.16
Event History
Jun 26, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-7496?
CVE-2017-7496 has a moderate severity rating due to its potential for local privilege escalation.
2
How do I fix CVE-2017-7496?
To fix CVE-2017-7496, update the Fedora Arm Installer to version 1.99.17 or newer.
3
What systems are affected by CVE-2017-7496?
CVE-2017-7496 affects Fedora Arm Installer versions up to and including 1.99.16.
4
What type of vulnerability is CVE-2017-7496?
CVE-2017-7496 is classified as a local privilege escalation vulnerability.
5
What causes CVE-2017-7496?
CVE-2017-7496 is caused by a lack of error condition checking during mount operations on insecure temporary directories.