PT-2010-1070 · Popt+3 · Popt+3
Michael Schröder
·
Published
2010-06-08
·
Updated
2021-08-23
·
CVE-2005-4889
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
popt version 1.9.1
RPM versions prior to 4.4.3
Description
The issue affects the confidentiality, integrity, and availability of protected information. It can be exploited remotely. A local user may gain privileges by creating a hard link to a vulnerable setuid or setgid file during the removal of an RPM package.
Recommendations
For popt version 1.9.1, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
For RPM versions prior to 4.4.3, update to version 4.4.3 or later to resolve the issue. As a temporary workaround, consider restricting access to setuid and setgid files to minimize the risk of exploitation.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Rpm
Red Hat
Popt