7.2
CVSSv2

CVE-2010-2059

Published: 08/06/2010 Updated: 13/02/2023
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

lib/fsm.c in RPM 4.8.0 and unspecified 4.7.x and 4.6.x versions, and RPM prior to 4.4.3, does not properly reset the metadata of an executable file during replacement of the file in an RPM package upgrade, which might allow local users to gain privileges by creating a hard link to a vulnerable (1) setuid or (2) setgid file.

Vulnerable Product Search on Vulmon Subscribe to Product

rpm rpm 2.3.5

rpm rpm 4.4.2.1

rpm rpm 1.4.3

rpm rpm 3.0.1

rpm rpm 4.1

rpm rpm 2.2.3.11

rpm rpm 2.4.4

rpm rpm 2.3.8

rpm rpm 2.0.6

rpm rpm 1.4.4

rpm rpm 4.4.2

rpm rpm 1.4.2\\/a

rpm rpm 2.4.1

rpm rpm 2.4.9

rpm rpm 2.6.7

rpm rpm 2..4.10

rpm rpm 1.4

rpm rpm 2.0.10

rpm rpm 2.4.5

rpm rpm 4.0.1

rpm rpm 2.2.11

rpm rpm 4.0.4

rpm rpm 2.2.1

rpm rpm 2.0.1

rpm rpm 1.4.2

rpm rpm 3.0.3

rpm rpm 2.0.7

rpm rpm 4.0.2

rpm rpm 2.2.8

rpm rpm 3.0.2

rpm rpm 1.2

rpm rpm 4.0.

rpm rpm 2.1.1

rpm rpm 4.3.3

rpm rpm 2.5.5

rpm rpm 2.0.8

rpm rpm 2.3

rpm rpm 4.4.2.2

rpm rpm 2.4.8

rpm rpm 3.0.4

rpm rpm 2.5.6

rpm rpm 2.0

rpm rpm 2.0.2

rpm rpm 2.3.2

rpm rpm 2.4.3

rpm rpm 2.4.2

rpm rpm 1.4.5

rpm rpm 2.0.11

rpm rpm 3.0.5

rpm rpm 1.3

rpm rpm 2.2.3

rpm rpm 2.2

rpm rpm 2.1.2

rpm rpm 2.3.9

rpm rpm 2.2.4

rpm rpm 2.2.9

rpm rpm 2.5.3

rpm rpm 2.2.6

rpm rpm 2.3.6

rpm rpm 2.5

rpm rpm 2.2.3.10

rpm rpm 2.0.5

rpm rpm 2.4.12

rpm rpm 2.5.4

rpm rpm 1.4.7

rpm rpm 3.0

rpm rpm 1.4.6

rpm rpm 2.5.2

rpm rpm 2.4.11

rpm rpm 2.0.9

rpm rpm 2.1

rpm rpm 2.2.10

rpm rpm 2.3.3

rpm rpm 2.3.7

rpm rpm 2.3.4

rpm rpm

rpm rpm 2.0.4

rpm rpm 1.3.1

rpm rpm 3.0.6

rpm rpm 2.0.3

rpm rpm 2.3.1

rpm rpm 4.0.3

rpm rpm 2.4.6

rpm rpm 2.5.1

rpm rpm 2.2.5

rpm rpm 2.2.2

rpm rpm 2.2.7

rpm rpm 4.8.0

rpm rpm 4.6.0

rpm rpm 4.7.2

rpm rpm 4.7.0

rpm rpm 4.6.1

rpm rpm 4.7.1

Vendor Advisories

Debian Bug report logs - #584257 rpm -- Fails to remove the SUID/SGID bits on package updates Package: rpm; Maintainer for rpm is RPM packaging team <team+pkg-rpm@trackerdebianorg>; Source for rpm is src:rpm (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Wed, 2 Jun 2010 17:54:01 UTC ...
Synopsis Moderate: rpm security update Type/Severity Security Advisory: Moderate Topic Updated rpm packages that fix two security issues are now available for RedHat Enterprise Linux 4The Red Hat Security Response Team has rated this update as having moderatesecurity impact Common Vulnerability Scoring Sy ...
Synopsis Moderate: rpm security and bug fix update Type/Severity Security Advisory: Moderate Topic Updated rpm packages that fix one security issue and one bug are nowavailable for Red Hat Enterprise Linux 5The Red Hat Security Response Team has rated this update as having moderatesecurity impact A Common ...