PT-2000-1655 · Helix Gnome · Helix-Update
Published
2000-10-20
·
Updated
2008-09-05
·
CVE-2000-0722
CVSS v2.0
6.2
Medium
| Vector | AV:L/AC:H/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Helix GNOME Updater helix-update version 0.5 and earlier
Description
The issue allows local users to install arbitrary RPM packages by creating the /tmp/helix-install installation directory before root has begun installing packages.
Recommendations
For helix-update version 0.5 and earlier, consider restricting access to the /tmp/helix-install directory to prevent unauthorized installation of RPM packages until a fix is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Helix-Update