4.6
CVSSv2

CVE-2004-2133

Published: 29/01/2004 Updated: 11/07/2017
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Certain third-party packages for CVSup 16.1h, such as SuSE Linux, contain untrusted paths in the ELF RPATH fields of certain executables, which could allow local users to execute arbitrary code by causing cvsup to link against malicious libraries that are created in world-writable directories such as /usr/src/packages.

Vulnerable Product Search on Vulmon Subscribe to Product

cvsup cvsup cvsup-16.1h-2.i386.rpm

cvsup cvsup cvsup-16.1h-36.i586.rpm

cvsup cvsup cvsup-16.1h-43.i586.rpm