PT-2010-1070 · Popt+3 · Popt+3
Michael Schröder
·
Publicado
2010-06-08
·
Atualizado
2021-08-23
·
CVE-2005-4889
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
popt version 1.9.1
RPM versions prior to 4.4.3
Description
The issue affects the confidentiality, integrity, and availability of protected information. It can be exploited remotely. A local user may gain privileges by creating a hard link to a vulnerable setuid or setgid file during the removal of an RPM package.
Recommendations
For popt version 1.9.1, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
For RPM versions prior to 4.4.3, update to version 4.4.3 or later to resolve the issue. As a temporary workaround, consider restricting access to setuid and setgid files to minimize the risk of exploitation.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Rpm
Red Hat
Popt