Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2017-7500
Description:It was found that rpm did not properly handle RPM installations when a destination path was a symbolic link to a directory, possibly changing ownership and permissions of an arbitrary directory, and RPM files being placed in an arbitrary destination. An attacker, with write access to a directory in which a subdirectory will be installed, could redirect that directory to an arbitrary location and gain root privilege.
Test IDs: 1.3.6.1.4.1.25623.1.1.2.2023.1174   1.3.6.1.4.1.25623.1.1.2.2019.2384   1.3.6.1.4.1.25623.1.1.2.2023.1153   1.3.6.1.4.1.25623.1.1.2.2022.2829   1.3.6.1.4.1.25623.1.1.2.2019.2658   1.3.6.1.4.1.25623.1.1.4.2018.2073.1   1.3.6.1.4.1.25623.1.1.2.2022.2855   1.3.6.1.4.1.25623.1.0.852078   1.3.6.1.4.1.25623.1.1.2.2022.2776   1.3.6.1.4.1.25623.1.1.2.2022.2741   1.3.6.1.4.1.25623.1.1.2.2023.1202   1.3.6.1.4.1.25623.1.1.2.2023.1232  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2017-7500




© 1998-2025 E-Soft Inc. All rights reserved.