Lucene search

K
ubuntucveUbuntu.comUB:CVE-2010-2059
HistoryJun 08, 2010 - 12:00 a.m.

CVE-2010-2059

2010-06-0800:00:00
ubuntu.com
ubuntu.com
8

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

0.0004 Low

EPSS

Percentile

10.3%

lib/fsm.c in RPM 4.8.0 and unspecified 4.7.x and 4.6.x versions, and RPM
before 4.4.3, does not properly reset the metadata of an executable file
during replacement of the file in an RPM package upgrade, which might allow
local users to gain privileges by creating a hard link to a vulnerable (1)
setuid or (2) setgid file.

Notes

Author Note
kees not used for package management

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

0.0004 Low

EPSS

Percentile

10.3%