{ "schema_version": "1.4.0", "id": "GHSA-f3f6-q22p-8fh5", "modified": "2022-05-14T02:44:33Z", "published": "2022-05-14T02:44:33Z", "aliases": [ "CVE-2010-2059" ], "details": "lib/fsm.c in RPM 4.8.0 and unspecified 4.7.x and 4.6.x versions, and RPM before 4.4.3, does not properly reset the metadata of an executable file during replacement of the file in an RPM package upgrade, which might allow local users to gain privileges by creating a hard link to a vulnerable (1) setuid or (2) setgid file.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2010-2059" }, { "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=125517" }, { "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=598775" }, { "type": "WEB", "url": "http://distrib-coffee.ipsl.jussieu.fr/pub/mirrors/rpm/files/rpm/rpm-4.4/rpm-4.4.3.tar.gz" }, { "type": "WEB", "url": "http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.html" }, { "type": "WEB", "url": "http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html" }, { "type": "WEB", "url": "http://lists.vmware.com/pipermail/security-announce/2011/000126.html" }, { "type": "WEB", "url": "http://marc.info/?l=oss-security&m=127559059928131&w=2" }, { "type": "WEB", "url": "http://rpm.org/gitweb?p=rpm.git%3Ba=commit%3Bh=ca2d6b2b484f1501eafdde02e1688409340d2383" }, { "type": "WEB", "url": "http://rpm.org/gitweb?p=rpm.git;a=commit;h=ca2d6b2b484f1501eafdde02e1688409340d2383" }, { "type": "WEB", "url": "http://secunia.com/advisories/40028" }, { "type": "WEB", "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2010:180" }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2010/06/02/2" }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2010/06/02/3" }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2010/06/03/5" }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2010/06/04/1" }, { "type": "WEB", "url": "http://www.osvdb.org/65143" }, { "type": "WEB", "url": "http://www.redhat.com/support/errata/RHSA-2010-0679.html" }, { "type": "WEB", "url": "http://www.securityfocus.com/archive/1/516909/100/0/threaded" }, { "type": "WEB", "url": "http://www.vmware.com/security/advisories/VMSA-2011-0004.html" }, { "type": "WEB", "url": "http://www.vupen.com/english/advisories/2011/0606" } ], "database_specific": { "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2010-06-08T18:30:00Z" } }