The installation script studioexpressinstall for Teradata Studio Express 15.12.00.00 creates files in /tmp insecurely. A malicious local user could create a symlink in /tmp and possibly clobber system files or perhaps elevate privileges.
References
Link Resource
http://www.securityfocus.com/bid/94255 Third Party Advisory VDB Entry
http://www.vapidlabs.com/advisory.php?v=174 Exploit Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: larry_cashdollar

Published: 2016-11-10T16:00:00

Updated: 2016-11-25T19:57:01

Reserved: 2016-09-09T00:00:00


Link: CVE-2016-7490

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2016-11-10T16:59:04.567

Modified: 2016-12-02T23:18:18.987


Link: CVE-2016-7490

JSON object: View

cve-icon Redhat Information

No data.