V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2021-35939
DEB
Medium

It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of th…

CVSS
6.5
Medium
EPSS
0.00
p37
Published
2021-01-01
Updated
2021-01-01
Description

It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to be created. A local unprivileged user who owns another ancestor directory could potentially use this flaw to gain root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Tags · CWE
CWE-59
CAPEC-17
CAPEC-35
CAPEC-76
CAPEC-132
Affected products
RpmRpmRpmRpmRpmRpmRpmRpmRpmRpmRpmRpmRpmRpmRpmRpmRpmRpmRpmRpm
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
Timeline
2021-01-01
Published
2021-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: L
Local (L)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: H
High (H)
User Interaction
UI: R
Required (R)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.005 · p37
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-35 · CWE-59
└ via CAPEC-35 · CWE-59
└ via CAPEC-132 · CWE-59
└ via CAPEC-35 · CWE-59
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
rpmTracked
rpmTracked
rpmTracked
rpmTracked
rpmTracked
rpmTracked
rpmTracked
rpmTracked
rpmTracked
rpmTracked
rpmTracked
rpmTracked
rpmTracked
rpmTracked
rpmTracked
rpmTracked
rpmTracked
rpmTracked
rpmTracked
rpmTracked
Showing first 20 of 26
Source databases
DEB
CVE
RED
UBU
Related vulnerabilities