CVE-2005-4889
published 2010-06-08CVE-2005-4889: lib/fsm.c in RPM before 4.4.3 does not properly reset the metadata of an executable file during deletion of the file in an RPM package removal, which might…
PriorityP424high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.32%
24.3th percentile
lib/fsm.c in RPM before 4.4.3 does not properly reset the metadata of an executable file during deletion of the file in an RPM package removal, which might allow local users to gain privileges by creating a hard link to a vulnerable (1) setuid or (2) setgid file, a related issue to CVE-2010-2059.
Affected
92 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | rpm | < rpm 4.7.0-1 (bookworm) | rpm 4.7.0-1 (bookworm) |
| rpm | rpm | <= 4.4.2.3 | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.2HIGH
vendor_debian7.2LOW
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-pfqv-vjx4-pmxj: lib/fsm
ghsa_unreviewed·2022-05-01·CVSS 7.2
CVE-2005-4889 [HIGH] GHSA-pfqv-vjx4-pmxj: lib/fsm
lib/fsm.c in RPM before 4.4.3 does not properly reset the metadata of an executable file during deletion of the file in an RPM package removal, which might allow local users to gain privileges by creating a hard link to a vulnerable (1) setuid or (2) setgid file, a related issue to CVE-2010-2059.
OSV
CVE-2005-4889: lib/fsm
osv·2010-06-08·CVSS 7.2
CVE-2005-4889 [HIGH] CVE-2005-4889: lib/fsm
lib/fsm.c in RPM before 4.4.3 does not properly reset the metadata of an executable file during deletion of the file in an RPM package removal, which might allow local users to gain privileges by creating a hard link to a vulnerable (1) setuid or (2) setgid file, a related issue to CVE-2010-2059.
Red Hat
rpm: fails to drop SUID/SGID bits on package removal
vendor_redhat·2010-06-01·CVSS 7.2
CVE-2005-4889 [HIGH] rpm: fails to drop SUID/SGID bits on package removal
rpm: fails to drop SUID/SGID bits on package removal
lib/fsm.c in RPM before 4.4.3 does not properly reset the metadata of an executable file during deletion of the file in an RPM package removal, which might allow local users to gain privileges by creating a hard link to a vulnerable (1) setuid or (2) setgid file, a related issue to CVE-2010-2059.
Debian
CVE-2005-4889: rpm - lib/fsm.c in RPM before 4.4.3 does not properly reset the metadata of an executa...
vendor_debian·2005·CVSS 7.2
CVE-2005-4889 [HIGH] CVE-2005-4889: rpm - lib/fsm.c in RPM before 4.4.3 does not properly reset the metadata of an executa...
lib/fsm.c in RPM before 4.4.3 does not properly reset the metadata of an executable file during deletion of the file in an RPM package removal, which might allow local users to gain privileges by creating a hard link to a vulnerable (1) setuid or (2) setgid file, a related issue to CVE-2010-2059.
Scope: local
bookworm: resolved (fixed in 4.7.0-1)
bullseye: resolved (fixed in 4.7.0-1)
forky: resolved (fixed in 4.7.0-1)
sid: resolved (fixed in 4.7.0-1)
trixie: resolved (fixed in 4.7.0-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2005-4889 rpm: fails to drop SUID/SGID bits on package removal
bugzilla·2010-08-20·CVSS 7.2
CVE-2005-4889 [HIGH] CVE-2005-4889 rpm: fails to drop SUID/SGID bits on package removal
CVE-2005-4889 rpm: fails to drop SUID/SGID bits on package removal
Common Vulnerabilities and Exposures assigned an identifier CVE-2005-4889 to the following vulnerability:
lib/fsm.c in RPM before 4.4.3 does not properly reset the metadata of an executable file during deletion of the file in an RPM package removal, which might allow local users to gain privileges by creating a hard link to a vulnerable (1) setuid or (2) setgid file, a related issue to CVE-2010-2059.
References:
https://bugzilla.redhat.com/show_bug.cgi?id=125517
https://bugzilla.redhat.com/show_bug.cgi?id=598775
http://xforce.iss.net/xforce/xfdb/59426
This issue was fixed in Fedora rpm some time ago via bug #125517. RPM versions in Red Hat Enterprise Linux 3 and 4 do not contain the fix and are affected.
Discussion:
T
Bugzilla
CVE-2005-4889 rpm: Updates leave hardlinked copies untouched.
bugzilla·2004-06-08·CVSS 7.2
CVE-2005-4889 [HIGH] CVE-2005-4889 rpm: Updates leave hardlinked copies untouched.
CVE-2005-4889 rpm: Updates leave hardlinked copies untouched.
If a malicious creates a hardlink to a buggy s-bit program the
system is still compromised even after a fixed version has been
installed. The attached fix removes the s-bits from files that
get updated.
Discussion:
Created attachment 100965
Proposed patch
---
Fedora Core 2 is now maintained by the Fedora Legacy project for
security updates only. If this problem is a security issue, please
reopen and reassign to the Fedora Legacy product. If it is not a
security issue and hasn't been resolved in the current FC3 updates or
in the FC4 test release, reopen and change the version to match.
---
Hmm, good question. I leave it to your security group to decide if it's a
security issue or not. For now, I've changed the product to F
http://distrib-coffee.ipsl.jussieu.fr/pub/mirrors/rpm/files/rpm/rpm-4.4/rpm-4.4.3.tar.gzhttp://www.mandriva.com/security/advisories?name=MDVSA-2010:180https://bugzilla.redhat.com/show_bug.cgi?id=125517https://bugzilla.redhat.com/show_bug.cgi?id=598775https://exchange.xforce.ibmcloud.com/vulnerabilities/59426http://distrib-coffee.ipsl.jussieu.fr/pub/mirrors/rpm/files/rpm/rpm-4.4/rpm-4.4.3.tar.gzhttp://www.mandriva.com/security/advisories?name=MDVSA-2010:180https://bugzilla.redhat.com/show_bug.cgi?id=125517https://bugzilla.redhat.com/show_bug.cgi?id=598775https://exchange.xforce.ibmcloud.com/vulnerabilities/59426
2010-06-08
Published