[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

MDVSA-2010:180 -- Mandriva rpm

ID: oval:org.secpod.oval:def:300188Date: (C)2012-01-07   (M)2023-11-09
Class: PATCHFamily: unix




A vulnerability has been found and corrected in rpm: lib/fsm.c in RPM 4.8.0 and unspecified 4.7.x and 4.6.x versions, and RPM before 4.4.3, does not properly reset the metadata of an executable file during replacement of the file in an RPM package upgrade, which might allow local users to gain privileges by creating a hard link to a vulnerable setuid or setgid file . The updated packages have been patched to correct this issue.

Platform:
Mandriva Linux 2009.0
Product:
rpm
Reference:
MDVSA-2010:180
CVE-2010-2059
CVE-2005-4889
CVE    2
CVE-2005-4889
CVE-2010-2059
CPE    1
cpe:/o:mandriva:linux:2009.0

© SecPod Technologies