Jump to content

Advisories MDVSA-2010:180: rpm


paul
 Share

Recommended Posts

A vulnerability has been found and corrected in rpm:

 

lib/fsm.c in RPM 4.8.0 and unspecified 4.7.x and 4.6.x versions, and

RPM before 4.4.3, does not properly reset the metadata of an executable

file during replacement of the file in an RPM package upgrade, which

might allow local users to gain privileges by creating a hard link

to a vulnerable (1) setuid or (2) setgid file (CVE-2010-2059).

 

The updated packages have been patched to correct this issue.

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
 Share

×
×
  • Create New...