Link following in rpm - CVE-2017-7500
Published: August 13, 2018 / Updated: July 17, 2020
Vulnerability details
The vulnerability allows a local authenticated user to execute arbitrary code.
It was found that rpm did not properly handle RPM installations when a destination path was a symbolic link to a directory, possibly changing ownership and permissions of an arbitrary directory, and RPM files being placed in an arbitrary destination. An attacker, with write access to a directory in which a subdirectory will be installed, could redirect that directory to an arbitrary location and gain root privilege.
Affected software
Amazon Linux AMI
Anolis OS
Opensuse
openEuler
Fedora
Juniper Secure Analytics (JSA)
webMethods Managed File Transfer
Storage Ceph
EMC Cloud Tiering Appliance
IBM Cloud Transformation Advisor
App Connect Enterprise Certified Container
IBM Security Verify Governance
rpm
rpm-plugin-prioreset
rpm-plugin-ima
rpm-plugin-fapolicyd
rpm-libs
rpm-devel
rpm-build-libs
rpm-build
python3-rpm
rpm-plugin-selinux
rpm-plugin-syslog
rpm-plugin-systemd-inhibit
rpm-sign
rpm-apidocs
rpm-cron
rpm-help
rpm-debuginfo
rpm-debugsource
python2-rpm
Dell EMC Unity Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
IBM Qradar SIEM
How to mitigate CVE-2017-7500
Juniper Secure Analytics (JSA) - update to 7.5.0 UP8 IF03
IBM Cloud Transformation Advisor - update to 3.10.0
rpm - addressed in versions 4.13.0.2-1.fc25, 4.13.0.2-1.fc26
rpm-plugin-prioreset - update to 4.14.3-27.0.5
rpm-plugin-ima - update to 4.14.3-27.0.5
rpm-plugin-fapolicyd - update to 4.14.3-27.0.5
rpm-libs - update to 4.14.3-27.0.5
rpm-devel - update to 4.14.3-27.0.5
rpm-build-libs - update to 4.14.3-27.0.5
rpm-build - update to 4.14.3-27.0.5
rpm - update to 4.14.3-27.0.5
python3-rpm - update to 4.14.3-27.0.5
rpm-plugin-selinux - update to 4.14.3-27.0.5
rpm-plugin-syslog - update to 4.14.3-27.0.5
rpm-plugin-systemd-inhibit - update to 4.14.3-27.0.5
rpm-sign - update to 4.14.3-27.0.5
rpm-apidocs - update to 4.14.3-27.0.5
rpm-cron - update to 4.14.3-27.0.5
rpm-help - update to 4.15.1-28
python3-rpm - update to 4.15.1-28
rpm-build - update to 4.15.1-28
rpm-libs - update to 4.15.1-28
rpm-debuginfo - update to 4.15.1-28
rpm-debugsource - update to 4.15.1-28
rpm-plugin-systemd-inhibit - update to 4.15.1-28
python2-rpm - update to 4.15.1-28
rpm-devel - update to 4.15.1-28
rpm - update to 4.15.1-28
rpm - update to 4.16.1.3-29
Dell EMC Unity Operating Environment (OE) - update to 5.0.0.0.5.116
Dell EMC Unity VSA Operating Environment (OE) - update to 5.0.0.0.5.116
App Connect Enterprise Certified Container - addressed in versions 5.0.15, 11.3.0
Storage Ceph - update to 7.0
IBM Qradar SIEM - update to 7.5.0 Update Pack 8 IF01
IBM Security Verify Governance - update to 10.0.2.0.4
EMC Cloud Tiering Appliance - update to 12.1.0.65
External References
Related Security Bulletins
- Link following in rpm-software-management rpm
- OpenSUSE Linux update for rpm
- OpenSUSE Linux update for rpm
- Multiple vulnerabilities in Dell EMC Unity Family
- Multiple vulnerabilities in Dell EMC Cloud Tiering Appliance Family
- Multiple vulnerabilities in IBM App Connect Enterprise Certified Container
- openEuler update for rpm
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in Juniper Secure Analytics (JSA)
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Amazon Linux AMI update for rpm
- Multiple vulnerabilities in IBM Storage Ceph
- Multiple vulnerabilities in IBM Security Verify Governance - Identity Manager
- Anolis OS update for rpm
- Fedora 26 update for rpm
- Fedora 25 update for rpm
- Multiple vulnerabilities in IBM webMethods Managed File Transfer