[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248149

 
 

909

 
 

194803

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2005-4889Date: (C)2010-06-08   (M)2023-12-22


lib/fsm.c in RPM before 4.4.3 does not properly reset the metadata of an executable file during deletion of the file in an RPM package removal, which might allow local users to gain privileges by creating a hard link to a vulnerable (1) setuid or (2) setgid file, a related issue to CVE-2010-2059.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 7.2
Exploit Score: 3.9
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: LOCAL
Access Complexity: LOW
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
MDVSA-2010:180
http://distrib-coffee.ipsl.jussieu.fr/pub/mirrors/rpm/files/rpm/rpm-4.4/rpm-4.4.3.tar.gz
https://bugzilla.redhat.com/show_bug.cgi?id=125517
https://bugzilla.redhat.com/show_bug.cgi?id=598775
rpm-setgid-privilege-escalation(59426)

CPE    84
cpe:/a:rpm:rpm:2.2.3.11
cpe:/a:rpm:rpm:4.0.2
cpe:/a:rpm:rpm:2.2.3.10
cpe:/a:rpm:rpm:4.0.3
...
CWE    1
CWE-264
OVAL    4
oval:org.secpod.oval:def:300188
oval:org.secpod.oval:def:200156
oval:org.secpod.oval:def:500300
oval:org.secpod.oval:def:200102
...

© SecPod Technologies