It was found that rpm did not properly handle RPM installations when a destination path was a symbolic link to a directory, possibly changing ownership and permissions of an arbitrary directory, and RPM files being placed in an arbitrary destination. An attacker, with write access to a directory in which a subdirectory will be installed, could redirect that directory to an arbitrary location and gain root privilege.
Conclusion & alert: CVE-2017-7500 is rated Moderate Risk (41/100): CVSS High severity, with low exploitation likelihood (EPSS 0.41%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.05% | 0.41% | +0.36% |
| 2 | 2026-06-06 | 0.05% | 0.05% | +0.01% |
| 3 | 2026-05-25 | — | 0.05% | — |
Full EPSS history (17 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.3 | 3.0 | HIGH |
|
1.3 | 5.9 | [email protected] |
| 7.8 | 3.0 | HIGH |
|
1.8 | 5.9 | [email protected] |
| 7.2 | 2.0 | HIGH |
|
3.9 | 10.0 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
unimportant | CVE-2017-7500 unimportant priority: Debian including 1 source packages (rpm), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): open 5. | https://security-tracker.debian.org/tracker/CVE-2017-7500 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2017-7500 |
suse
|
high | CVE-2017-7500 severity important: SUSE including 344 source package names (0.1.0:rpm-4.14.1-10.3.1, 0.1.75:rpm-4.14.1-10.3.1, …), 585 product×package rows across 157 product lines (Container caasp/v4/389-ds, Container caasp/v4/busybox, … (157 product lines)): Fixed 270, Known Affected 231, Known Not Affected 84. | https://www.suse.com/security/cve/CVE-2017-7500/ |
ubuntu
|
low | CVE-2017-7500 low priority: Ubuntu including 1 source packages (rpm), 22 status rows across 22 suites (artful, bionic, cosmic, disco, eoan, focal, groovy, hirsute, impish, jammy, kinetic, lunar, mantic, noble, oracular, plucky, questing, trusty, upstream, xenial, yakkety, zesty): not-affected 13, ignored 6, needed 3. | https://ubuntu.com/security/CVE-2017-7500 |
| URL | Tags |
|---|---|
| https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-7500 | Issue Tracking |
| https://github.com/rpm-software-management/rpm/commit/c815822c8bdb138066ff58c624ae83e3a12ebfa9 | Third Party Advisory |
| https://github.com/rpm-software-management/rpm/commit/f2d3be2a8741234faaa96f5fd05fdfdc75779a79 | Third Party Advisory |