CVE-2021-35939
published 2022-08-26CVE-2021-35939: It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to be…
medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to be created. A local unprivileged user who owns another ancestor directory could potentially use this flaw to gain root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | rpm | < rpm 4.18.0+dfsg-1 (bookworm) | rpm 4.18.0+dfsg-1 (bookworm) |
| msrc | cbl2_rpm_4.18.0-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| msrc | cm1_rpm_4.14.2-15_on_cbl_mariner_1.0 | — | — |
| redhat | enterprise_linux | — | — |
| rpm | rpm | < 4.18 | 4.18 |
| rpm | rpm | >= 0 < 4.18.0+dfsg-1 | 4.18.0+dfsg-1 |
| rpm | rpm | >= 0 < 4.18.0+dfsg-1 | 4.18.0+dfsg-1 |
| rpm | rpm | >= 0 < 4.18.0+dfsg-1 | 4.18.0+dfsg-1 |
CVSS provenance
nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
Microsoft
It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to be created. A local unprivileged user who owns anot
vendor_msrc·2022-08-09·CVSS 6.7
CVE-2021-35939 [HIGH] CWE-59 It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to be created. A local unprivileged user who owns anot
It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to be created. A local unprivileged user who owns another ancestor directory could potentially use this flaw to gain root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed
Red Hat
rpm: checks for unsafe symlinks are not performed for intermediary directories
vendor_redhat·2021-06-30·CVSS 7.3
CVE-2021-35939 [HIGH] CWE-59 rpm: checks for unsafe symlinks are not performed for intermediary directories
rpm: checks for unsafe symlinks are not performed for intermediary directories
It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to be created. A local unprivileged user who owns another ancestor directory could potentially use this flaw to gain root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to be created. A local unprivileged user who owns another ancestor directory could potentially use this flaw to gain root privileges. The highest threat from this vulnerability
Debian
CVE-2021-35939: rpm - It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: th...
vendor_debian·2021·CVSS 7.3
CVE-2021-35939 [HIGH] CVE-2021-35939: rpm - It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: th...
It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to be created. A local unprivileged user who owns another ancestor directory could potentially use this flaw to gain root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Scope: local
bookworm: resolved (fixed in 4.18.0+dfsg-1)
bullseye: open
forky: resolved (fixed in 4.18.0+dfsg-1)
sid: resolved (fixed in 4.18.0+dfsg-1)
trixie: resolved (fixed in 4.18.0+dfsg-1)
GHSA
GHSA-prgv-w33h-5m73: It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to b
ghsa_unreviewed·2022-08-27·CVSS 7.3
CVE-2021-35939 [HIGH] CWE-59 GHSA-prgv-w33h-5m73: It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to b
It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to be created. A local unprivileged user who owns another ancestor directory could potentially use this flaw to gain root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
OSV
CVE-2021-35939: It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to b
osv·2022-08-26·CVSS 7.8
CVE-2021-35939 [HIGH] CVE-2021-35939: It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to b
It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to be created. A local unprivileged user who owns another ancestor directory could potentially use this flaw to gain root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/security/cve/CVE-2021-35939https://bugzilla.redhat.com/show_bug.cgi?id=1964129https://github.com/rpm-software-management/rpm/commit/96ec957e281220f8e137a2d5eb23b83a6377d556https://github.com/rpm-software-management/rpm/pull/1919https://rpm.org/wiki/Releases/4.18.0https://security.gentoo.org/glsa/202210-22https://access.redhat.com/security/cve/CVE-2021-35939https://bugzilla.redhat.com/show_bug.cgi?id=1964129https://github.com/rpm-software-management/rpm/commit/96ec957e281220f8e137a2d5eb23b83a6377d556https://github.com/rpm-software-management/rpm/pull/1919https://rpm.org/wiki/Releases/4.18.0https://security.gentoo.org/glsa/202210-22
2022-08-26
Published