CVE Vulnerabilities

CVE-2010-2059

Published: Jun 08, 2010 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
1.9 MODERATE
AV:L/AC:M/Au:N/C:N/I:P/A:N
RedHat/V3
Ubuntu
NEGLIGIBLE

lib/fsm.c in RPM 4.8.0 and unspecified 4.7.x and 4.6.x versions, and RPM before 4.4.3, does not properly reset the metadata of an executable file during replacement of the file in an RPM package upgrade, which might allow local users to gain privileges by creating a hard link to a vulnerable (1) setuid or (2) setgid file.

Affected Software

Name Vendor Start Version End Version
Rpm Rpm * 4.4.2.3 (including)
Rpm Rpm 1.2 (including) 1.2 (including)
Rpm Rpm 1.3 (including) 1.3 (including)
Rpm Rpm 1.3.1 (including) 1.3.1 (including)
Rpm Rpm 1.4 (including) 1.4 (including)
Rpm Rpm 1.4.2 (including) 1.4.2 (including)
Rpm Rpm 1.4.2/a (including) 1.4.2/a (including)
Rpm Rpm 1.4.3 (including) 1.4.3 (including)
Rpm Rpm 1.4.4 (including) 1.4.4 (including)
Rpm Rpm 1.4.5 (including) 1.4.5 (including)
Rpm Rpm 1.4.6 (including) 1.4.6 (including)
Rpm Rpm 1.4.7 (including) 1.4.7 (including)
Rpm Rpm 2..4.10 (including) 2..4.10 (including)
Rpm Rpm 2.0 (including) 2.0 (including)
Rpm Rpm 2.0.1 (including) 2.0.1 (including)
Rpm Rpm 2.0.2 (including) 2.0.2 (including)
Rpm Rpm 2.0.3 (including) 2.0.3 (including)
Rpm Rpm 2.0.4 (including) 2.0.4 (including)
Rpm Rpm 2.0.5 (including) 2.0.5 (including)
Rpm Rpm 2.0.6 (including) 2.0.6 (including)
Rpm Rpm 2.0.7 (including) 2.0.7 (including)
Rpm Rpm 2.0.8 (including) 2.0.8 (including)
Rpm Rpm 2.0.9 (including) 2.0.9 (including)
Rpm Rpm 2.0.10 (including) 2.0.10 (including)
Rpm Rpm 2.0.11 (including) 2.0.11 (including)
Rpm Rpm 2.1 (including) 2.1 (including)
Rpm Rpm 2.1.1 (including) 2.1.1 (including)
Rpm Rpm 2.1.2 (including) 2.1.2 (including)
Rpm Rpm 2.2 (including) 2.2 (including)
Rpm Rpm 2.2.1 (including) 2.2.1 (including)
Rpm Rpm 2.2.2 (including) 2.2.2 (including)
Rpm Rpm 2.2.3 (including) 2.2.3 (including)
Rpm Rpm 2.2.3.10 (including) 2.2.3.10 (including)
Rpm Rpm 2.2.3.11 (including) 2.2.3.11 (including)
Rpm Rpm 2.2.4 (including) 2.2.4 (including)
Rpm Rpm 2.2.5 (including) 2.2.5 (including)
Rpm Rpm 2.2.6 (including) 2.2.6 (including)
Rpm Rpm 2.2.7 (including) 2.2.7 (including)
Rpm Rpm 2.2.8 (including) 2.2.8 (including)
Rpm Rpm 2.2.9 (including) 2.2.9 (including)
Rpm Rpm 2.2.10 (including) 2.2.10 (including)
Rpm Rpm 2.2.11 (including) 2.2.11 (including)
Rpm Rpm 2.3 (including) 2.3 (including)
Rpm Rpm 2.3.1 (including) 2.3.1 (including)
Rpm Rpm 2.3.2 (including) 2.3.2 (including)
Rpm Rpm 2.3.3 (including) 2.3.3 (including)
Rpm Rpm 2.3.4 (including) 2.3.4 (including)
Rpm Rpm 2.3.5 (including) 2.3.5 (including)
Rpm Rpm 2.3.6 (including) 2.3.6 (including)
Rpm Rpm 2.3.7 (including) 2.3.7 (including)
Rpm Rpm 2.3.8 (including) 2.3.8 (including)
Rpm Rpm 2.3.9 (including) 2.3.9 (including)
Rpm Rpm 2.4.1 (including) 2.4.1 (including)
Rpm Rpm 2.4.2 (including) 2.4.2 (including)
Rpm Rpm 2.4.3 (including) 2.4.3 (including)
Rpm Rpm 2.4.4 (including) 2.4.4 (including)
Rpm Rpm 2.4.5 (including) 2.4.5 (including)
Rpm Rpm 2.4.6 (including) 2.4.6 (including)
Rpm Rpm 2.4.8 (including) 2.4.8 (including)
Rpm Rpm 2.4.9 (including) 2.4.9 (including)
Rpm Rpm 2.4.11 (including) 2.4.11 (including)
Rpm Rpm 2.4.12 (including) 2.4.12 (including)
Rpm Rpm 2.5 (including) 2.5 (including)
Rpm Rpm 2.5.1 (including) 2.5.1 (including)
Rpm Rpm 2.5.2 (including) 2.5.2 (including)
Rpm Rpm 2.5.3 (including) 2.5.3 (including)
Rpm Rpm 2.5.4 (including) 2.5.4 (including)
Rpm Rpm 2.5.5 (including) 2.5.5 (including)
Rpm Rpm 2.5.6 (including) 2.5.6 (including)
Rpm Rpm 2.6.7 (including) 2.6.7 (including)
Rpm Rpm 3.0 (including) 3.0 (including)
Rpm Rpm 3.0.1 (including) 3.0.1 (including)
Rpm Rpm 3.0.2 (including) 3.0.2 (including)
Rpm Rpm 3.0.3 (including) 3.0.3 (including)
Rpm Rpm 3.0.4 (including) 3.0.4 (including)
Rpm Rpm 3.0.5 (including) 3.0.5 (including)
Rpm Rpm 3.0.6 (including) 3.0.6 (including)
Rpm Rpm 4.0. (including) 4.0. (including)
Rpm Rpm 4.0.1 (including) 4.0.1 (including)
Rpm Rpm 4.0.2 (including) 4.0.2 (including)
Rpm Rpm 4.0.3 (including) 4.0.3 (including)
Rpm Rpm 4.0.4 (including) 4.0.4 (including)
Rpm Rpm 4.1 (including) 4.1 (including)
Rpm Rpm 4.3.3 (including) 4.3.3 (including)
Rpm Rpm 4.4.2 (including) 4.4.2 (including)
Rpm Rpm 4.4.2.1 (including) 4.4.2.1 (including)
Rpm Rpm 4.4.2.2 (including) 4.4.2.2 (including)
Red Hat Enterprise Linux 4 RedHat rpm-0:4.3.3-33_nonptl.el4_8.1 *
Red Hat Enterprise Linux 5 RedHat rpm-0:4.4.2.3-20.el5_5.1 *
Rpm Ubuntu dapper *
Rpm Ubuntu hardy *
Rpm Ubuntu jaunty *
Rpm Ubuntu karmic *
Rpm Ubuntu lucid *
Rpm Ubuntu maverick *
Rpm Ubuntu upstream *

References