PT-2010-1070 · Popt+3 · Popt+3

Michael Schröder

·

Publicado

2010-06-08

·

Atualizado

2021-08-23

·

CVE-2005-4889

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions popt version 1.9.1 RPM versions prior to 4.4.3
Description The issue affects the confidentiality, integrity, and availability of protected information. It can be exploited remotely. A local user may gain privileges by creating a hard link to a vulnerable setuid or setgid file during the removal of an RPM package.
Recommendations For popt version 1.9.1, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For RPM versions prior to 4.4.3, update to version 4.4.3 or later to resolve the issue. As a temporary workaround, consider restricting access to setuid and setgid files to minimize the risk of exploitation.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2016-2427
ALT-PU-2021-2518
ALT-PU-2021-2600
BDU:2015-06484
CVE-2005-4889
RHSA-2010:0678
RHSA-2010_0678

Produtos afetados

Alt Linux
Rpm
Red Hat
Popt