Vulnerability Details CVE-2017-7500
It was found that rpm did not properly handle RPM installations when a destination path was a symbolic link to a directory, possibly changing ownership and permissions of an arbitrary directory, and RPM files being placed in an arbitrary destination. An attacker, with write access to a directory in which a subdirectory will be installed, could redirect that directory to an arbitrary location and gain root privilege.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 26.1%
CVSS Severity
CVSS v3 Score 7.3
CVSS v2 Score 7.2
Products affected by CVE-2017-7500
-
cpe:2.3:a:rpm:rpm:4.13.0.1
-
cpe:2.3:a:rpm:rpm:4.14.0.0