PT-2010-1220 · Debian · Dpkg

Matt Mccutchen

·

Publicado

2010-06-08

·

Atualizado

2017-08-17

·

CVE-2004-2768

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions dpkg version 1.9.21
Description The issue is related to the replacement of files during package upgrades, where the metadata of a file is not properly reset. This could potentially allow local users to gain privileges by creating a hard link to a setuid file, setgid file, or device.
Recommendations For dpkg version 1.9.21, update to a newer version that contains a fix for this issue to prevent potential privilege escalation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2004-2768

Produtos afetados

Dpkg