affected: - ecosystem_specific: {} package: ecosystem: PyPI name: instack purl: pkg:pypi/instack ranges: - events: - introduced: '0' - last_affected: 7.2.0 - last_affected: 6.1.0 - last_affected: 5.3.0 type: ECOSYSTEM versions: - 0.0.9.dev4 - 5.0.0 - 5.0.0.0b1 - 5.0.0.0b2 - 5.1.0 aliases: - CVE-2017-7549 details: A flaw was found in instack-undercloud 7.2.0 as packaged in Red Hat OpenStack Platform Pike, 6.1.0 as packaged in Red Hat OpenStack Platform Oacta, 5.3.0 as packaged in Red Hat OpenStack Newton, where pre-install and security policy scripts used insecure temporary files. A local user could exploit this flaw to conduct a symbolic-link attack, allowing them to overwrite the contents of arbitrary files. id: PYSEC-2017-152 modified: '2026-05-21T14:54:30.554896Z' published: '2017-09-21T21:29:00.447Z' references: - type: ADVISORY url: http://www.securityfocus.com/bid/100407 - type: ADVISORY url: https://access.redhat.com/errata/RHSA-2017:2557 - type: ADVISORY url: https://access.redhat.com/errata/RHSA-2017:2649 - type: ADVISORY url: https://access.redhat.com/errata/RHSA-2017:2687 - type: ADVISORY url: https://access.redhat.com/errata/RHSA-2017:2693 - type: ADVISORY url: https://access.redhat.com/errata/RHSA-2017:2726 - type: REPORT url: https://bugzilla.redhat.com/show_bug.cgi?id=1477403 severity: - score: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N type: CVSS_V3