Link following in rpm - CVE-2017-7501

 

Link following in rpm - CVE-2017-7501

Published: November 22, 2017 / Updated: July 17, 2020


Vulnerability identifier: #VU31396
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-7501
CWE-ID: CWE-59
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local authenticated user to execute arbitrary code.

It was found that versions of rpm before 4.13.0.2 use temporary files with predictable names when installing an RPM. An attacker with ability to write in a directory where files will be installed could create symbolic links to an arbitrary location and modify content, and possibly permissions to arbitrary files, which could be used for denial of service or possibly privilege escalation.


Affected software

rpm
Amazon Linux AMI
Anolis OS
openEuler
Fedora
Opensuse
Juniper Secure Analytics (JSA)
webMethods Managed File Transfer
Storage Ceph
EMC Cloud Tiering Appliance
IBM Cloud Transformation Advisor
App Connect Enterprise Certified Container
IBM Security Verify Governance
rpm
rpm-plugin-prioreset
rpm-plugin-ima
rpm-plugin-fapolicyd
rpm-libs
rpm-devel
rpm-build-libs
rpm-build
python3-rpm
rpm-plugin-selinux
rpm-plugin-syslog
rpm-plugin-systemd-inhibit
rpm-sign
rpm-apidocs
rpm-cron
rpm-help
rpm-debuginfo
rpm-debugsource
python2-rpm
Dell EMC Unity Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
IBM Qradar SIEM

How to mitigate CVE-2017-7501

Install update from vendor's website.

rpm - update to 4.13.0.3
Juniper Secure Analytics (JSA) - update to 7.5.0 UP8 IF03
IBM Cloud Transformation Advisor - update to 3.10.0
rpm - addressed in versions 4.13.0.2-1.fc25, 4.13.0.2-1.fc26
rpm-plugin-prioreset - update to 4.14.3-27.0.5
rpm-plugin-ima - update to 4.14.3-27.0.5
rpm-plugin-fapolicyd - update to 4.14.3-27.0.5
rpm-libs - update to 4.14.3-27.0.5
rpm-devel - update to 4.14.3-27.0.5
rpm-build-libs - update to 4.14.3-27.0.5
rpm-build - update to 4.14.3-27.0.5
rpm - update to 4.14.3-27.0.5
python3-rpm - update to 4.14.3-27.0.5
rpm-plugin-selinux - update to 4.14.3-27.0.5
rpm-plugin-syslog - update to 4.14.3-27.0.5
rpm-plugin-systemd-inhibit - update to 4.14.3-27.0.5
rpm-sign - update to 4.14.3-27.0.5
rpm-apidocs - update to 4.14.3-27.0.5
rpm-cron - update to 4.14.3-27.0.5
rpm-help - update to 4.15.1-28
python3-rpm - update to 4.15.1-28
rpm-build - update to 4.15.1-28
rpm-libs - update to 4.15.1-28
rpm-debuginfo - update to 4.15.1-28
rpm-debugsource - update to 4.15.1-28
rpm-plugin-systemd-inhibit - update to 4.15.1-28
python2-rpm - update to 4.15.1-28
rpm-devel - update to 4.15.1-28
rpm - update to 4.15.1-28
rpm - update to 4.16.1.3-29
Dell EMC Unity Operating Environment (OE) - update to 5.0.0.0.5.116
Dell EMC Unity VSA Operating Environment (OE) - update to 5.0.0.0.5.116
App Connect Enterprise Certified Container - addressed in versions 5.0.15, 11.3.0
Storage Ceph - update to 7.0
IBM Qradar SIEM - update to 7.5.0 Update Pack 8 IF01
IBM Security Verify Governance - update to 10.0.2.0.4
EMC Cloud Tiering Appliance - update to 12.1.0.65

External References

Related Security Bulletins