Lucene search

K
cvelistMitreCVELIST:CVE-2010-2198
HistoryOct 03, 2022 - 4:21 p.m.

CVE-2010-2198

2022-10-0316:21:08
mitre
www.cve.org
rpm 4.8.0
executable file
upgrade
deletion
local users
privileges
access restrictions
hard link
posix file
selinux context
cve-2010-2198

7.7 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

10.1%

lib/fsm.c in RPM 4.8.0 and earlier does not properly reset the metadata of an executable file during replacement of the file in an RPM package upgrade or deletion of the file in an RPM package removal, which might allow local users to gain privileges or bypass intended access restrictions by creating a hard link to a vulnerable file that has (1) POSIX file capabilities or (2) SELinux context information, a related issue to CVE-2010-2059.

7.7 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

10.1%