CVE-2017-7500: High severity rpm rpm vulnerability
It was found that rpm did not properly handle RPM installations when a destination path was a symbolic link to a directory, possibly changing ownership and permissions of an arbitrary directory, and RPM files being placed in an arbitrary destination. An attacker, with write access to a directory in which a subdirectory will be installed, could redirect that directory to an arbitrary location and gain root privilege.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-7500?
CVE-2017-7500 is a vulnerability found in the RPM package manager that allows an attacker with write access to a directory to change ownership and permissions of arbitrary directories.
What is the severity of CVE-2017-7500?
The severity of CVE-2017-7500 is high with a CVSS score of 7.8.
Which software is affected by CVE-2017-7500?
The RPM package manager versions 4.13.0.0 to 4.13.0.2, 4.14.0.0-rc1, and 4.14.0.0-rc2 are affected by CVE-2017-7500.
How can an attacker exploit CVE-2017-7500?
An attacker with write access to a directory in the RPM package installation path can exploit CVE-2017-7500.
Are there any references for more information about CVE-2017-7500?
Yes, you can find more information about CVE-2017-7500 at the following references: - [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-7500) - [RPM Software Management Commit 1](https://github.com/rpm-software-management/rpm/commit/c815822c8bdb138066ff58c624ae83e3a12ebfa9) - [RPM Software Management Commit 2](https://github.com/rpm-software-management/rpm/commit/f2d3be2a8741234faaa96f5fd05fdfdc75779a79)