Mandriva Linux Security Advisory : rpm (MDVSA-2010:180)

This script is Copyright (C) 2010-2013 Tenable Network Security, Inc.


Synopsis :

The remote Mandriva Linux host is missing one or more security
updates.

Description :

A vulnerability has been found and corrected in rpm :

lib/fsm.c in RPM 4.8.0 and unspecified 4.7.x and 4.6.x versions, and
RPM before 4.4.3, does not properly reset the metadata of an
executable file during replacement of the file in an RPM package
upgrade, which might allow local users to gain privileges by creating
a hard link to a vulnerable (1) setuid or (2) setgid file
(CVE-2010-2059).

The updated packages have been patched to correct this issue.

Solution :

Update the affected packages.

Risk factor :

High / CVSS Base Score : 7.2
(CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)
CVSS Temporal Score : 6.0
(CVSS2#E:F/RL:OF/RC:C)
Public Exploit Available : true

Family: Mandriva Local Security Checks

Nessus Plugin ID: 49209 (mandriva_MDVSA-2010-180.nasl)

Bugtraq ID: 40512

CVE ID: CVE-2005-4889
CVE-2010-2059

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now