Wednesday, September 15, 2010

rpm: Privilege Escalation

Users of rpm please be advised of a Privilege Escalation vulnerability that has been identified.

To view this vulnerability, possible remedies, and others please check out the Security Advisories at Critical Watch (http://criticalwatch.com/support/security-advisories.aspx)

Amplify’d from www.criticalwatch.com
MDVSA-2010:180: [MDVSA-2010:180] rpm Privilege Escalation
Problem Description:



A vulnerability has been found and corrected in rpm:



lib/fsm.c in RPM 4.8.0 and unspecified 4.7.x and 4.6.x versions, and

RPM before 4.4.3, does not properly reset the metadata of an executable

file during replacement of the file in an RPM package upgrade, which

might allow local users to gain privileges by creating a hard link

to a vulnerable (1) setuid or (2) setgid file (CVE-2010-2059).


Read more at www.criticalwatch.com
 

No comments:

Post a Comment