PT-2010-1070 · Popt+3 · Popt+3

Michael Schröder

·

Published

2010-06-08

·

Updated

2021-08-23

·

CVE-2005-4889

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions popt version 1.9.1 RPM versions prior to 4.4.3
Description The issue affects the confidentiality, integrity, and availability of protected information. It can be exploited remotely. A local user may gain privileges by creating a hard link to a vulnerable setuid or setgid file during the removal of an RPM package.
Recommendations For popt version 1.9.1, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For RPM versions prior to 4.4.3, update to version 4.4.3 or later to resolve the issue. As a temporary workaround, consider restricting access to setuid and setgid files to minimize the risk of exploitation.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-2427
ALT-PU-2021-2518
ALT-PU-2021-2600
BDU:2015-06484
CVE-2005-4889
RHSA-2010:0678
RHSA-2010_0678

Affected Products

Alt Linux
Rpm
Red Hat
Popt