High severity7.8NVD Advisory· Published Nov 22, 2017· Updated May 13, 2026
CVE-2017-7501
CVE-2017-7501
Description
It was found that versions of rpm before 4.13.0.2 use temporary files with predictable names when installing an RPM. An attacker with ability to write in a directory where files will be installed could create symbolic links to an arbitrary location and modify content, and possibly permissions to arbitrary files, which could be used for denial of service or possibly privilege escalation.
Affected products
2- Red Hat, Inc./rpmv5Range: before 4.13.0.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- github.com/rpm-software-management/rpm/commit/404ef011c300207cdb1e531670384564aae04bdcnvdIssue TrackingPatch
- lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3Envd
- lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3Envd
- security.gentoo.org/glsa/201811-22nvd
News mentions
0No linked articles in our index yet.