5.8
CVSSv2

CVE-2010-2197

Published: 08/06/2010 Updated: 17/08/2017
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:P

Vulnerability Summary

rpmbuild in RPM 4.8.0 and previous versions does not properly parse the syntax of spec files, which allows user-assisted remote malicious users to remove home directories via vectors involving a ;~ (semicolon tilde) sequence in a Name tag.

Vulnerable Product Search on Vulmon Subscribe to Product

rpm rpm 1.4.2

rpm rpm 1.3.1

rpm rpm 1.2

rpm rpm 2.0

rpm rpm 1.4.3

rpm rpm 1.4.4

rpm rpm 2.0.1

rpm rpm 2.0.2

rpm rpm 2.0.9

rpm rpm 2.0.10

rpm rpm 2.2.7

rpm rpm 2.2.8

rpm rpm 2.2

rpm rpm 2.3

rpm rpm 2.3.7

rpm rpm 2.3.8

rpm rpm 2.4.4

rpm rpm 2.4.5

rpm rpm 2.5.1

rpm rpm 2.5.2

rpm rpm 3.0.2

rpm rpm 3.0.3

rpm rpm 4.0.1

rpm rpm 4.0.2

rpm rpm 4.0.3

rpm rpm 1.4.2\\/a

rpm rpm 4.4.2.3

rpm rpm 2.0.7

rpm rpm 2.0.8

rpm rpm 2.2.5

rpm rpm 2.2.6

rpm rpm 2.0.11

rpm rpm 2.2.10

rpm rpm 2.3.5

rpm rpm 2.3.6

rpm rpm 2.4.2

rpm rpm 2.4.3

rpm rpm 2.4.11

rpm rpm 2.4.12

rpm rpm 2.5

rpm rpm 3.0.1

rpm rpm 1.4

rpm rpm 4.0.

rpm rpm 4.4.2.2

rpm rpm 4.4.2

rpm rpm 1.4.7

rpm rpm 1.3

rpm rpm 2.0.5

rpm rpm 2.0.6

rpm rpm 2.2.3

rpm rpm 2.2.4

rpm rpm 2.1

rpm rpm 2.1.1

rpm rpm 2.1.2

rpm rpm 2.3.3

rpm rpm 2.3.4

rpm rpm 2.2.3.11

rpm rpm 2.4.1

rpm rpm 2.4.9

rpm rpm 2..4.10

rpm rpm 2.5.5

rpm rpm 2.5.6

rpm rpm 3.0.6

rpm rpm 3.0

rpm rpm 4.3.3

rpm rpm 4.4.2.1

rpm rpm 1.4.5

rpm rpm 1.4.6

rpm rpm 2.0.3

rpm rpm 2.0.4

rpm rpm 2.2.1

rpm rpm 2.2.2

rpm rpm 2.2.9

rpm rpm 2.2.11

rpm rpm 2.3.1

rpm rpm 2.3.2

rpm rpm 2.3.9

rpm rpm 2.2.3.10

rpm rpm 2.4.6

rpm rpm 2.6.7

rpm rpm 2.4.8

rpm rpm 2.5.3

rpm rpm 2.5.4

rpm rpm 3.0.4

rpm rpm 3.0.5

rpm rpm 4.0.4

rpm rpm 4.1

rpm rpm

rpm rpm 4.7.1

rpm rpm 4.7.2

rpm rpm 4.6.1

rpm rpm 4.7.0

rpm rpm 4.6.0

Vendor Advisories

Debian Bug report logs - #584257 rpm -- Fails to remove the SUID/SGID bits on package updates Package: rpm; Maintainer for rpm is RPM packaging team <team+pkg-rpm@trackerdebianorg>; Source for rpm is src:rpm (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Wed, 2 Jun 2010 17:54:01 UTC ...