CVE-2010-2059
published 2010-06-08CVE-2010-2059: lib/fsm.c in RPM 4.8.0 and unspecified 4.7.x and 4.6.x versions, and RPM before 4.4.3, does not properly reset the metadata of an executable file during…
PriorityP427high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.40%
32.2th percentile
lib/fsm.c in RPM 4.8.0 and unspecified 4.7.x and 4.6.x versions, and RPM before 4.4.3, does not properly reset the metadata of an executable file during replacement of the file in an RPM package upgrade, which might allow local users to gain privileges by creating a hard link to a vulnerable (1) setuid or (2) setgid file.
Affected
117 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | dpkg | < dpkg 1.10.19 (bookworm) | dpkg 1.10.19 (bookworm) |
| debian | dpkg | — | — |
| debian | dpkg | >= 0 < 1.10.19 | 1.10.19 |
| debian | dpkg | >= 0 < 1.10.19 | 1.10.19 |
| debian | dpkg | >= 0 < 1.10.19 | 1.10.19 |
| debian | dpkg | >= 0 < 1.10.19 | 1.10.19 |
| debian | rpm | < rpm 4.7.0-1 (bookworm) | rpm 4.7.0-1 (bookworm) |
| debian | rpm | < rpm 4.8.1-1 (bookworm) | rpm 4.8.1-1 (bookworm) |
| debian | rpm | — | — |
| rpm | rpm | <= 4.8.0 | — |
| rpm | rpm | <= 4.4.2.3 | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.2HIGH
vendor_debian7.2LOW
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware ESX/ESXi SLPD denial of service vulnerability and ESX third party updates for Service Console packages bind, pam, and rpm.
vendor_vmware·2011-03-07·CVSS 5.0
CVE-2010-2059 [MEDIUM] VMware ESX/ESXi SLPD denial of service vulnerability and ESX third party updates for Service Console packages bind, pam, and rpm.
VMSA-2011-0004: VMware ESX/ESXi SLPD denial of service vulnerability and ESX third party updates for Service Console packages bind, pam, and rpm.
a. Service Location Protocol daemon DoS This patch fixes a denial-of-service vulnerability in the Service Location Protocol daemon (SLPD). Exploitation of this vulnerability could cause SLPD to consume significant CPU resources. VMware would like to thank Nicolas Gregoire and US CERT for reporting this issue to us. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the names CVE-2010-3609 to this issue. Column 4 of the following table lists the action required to remediate the vulnerability in each release, if a solution is available. VMware Product ============= Product Version ======= Running on ======= Replace with/
Red Hat
rpm: fails to drop POSIX file capabilities on package upgrade or removal
vendor_redhat·2010-06-01·CVSS 7.2
CVE-2010-2198 [HIGH] rpm: fails to drop POSIX file capabilities on package upgrade or removal
rpm: fails to drop POSIX file capabilities on package upgrade or removal
lib/fsm.c in RPM 4.8.0 and earlier does not properly reset the metadata of an executable file during replacement of the file in an RPM package upgrade or deletion of the file in an RPM package removal, which might allow local users to gain privileges or bypass intended access restrictions by creating a hard link to a vulnerable file that has (1) POSIX file capabilities or (2) SELinux context information, a related issue to CVE-2010-2059.
Statement: Not vulnerable. RPM as provided with Red Hat Enterprise 3, 4, and 5 do not support POSIX capabilities.
Red Hat
rpm: fails to drop SUID/SGID bits on package upgrade
vendor_redhat·2010-06-01·CVSS 7.2
CVE-2010-2059 [HIGH] rpm: fails to drop SUID/SGID bits on package upgrade
rpm: fails to drop SUID/SGID bits on package upgrade
lib/fsm.c in RPM 4.8.0 and unspecified 4.7.x and 4.6.x versions, and RPM before 4.4.3, does not properly reset the metadata of an executable file during replacement of the file in an RPM package upgrade, which might allow local users to gain privileges by creating a hard link to a vulnerable (1) setuid or (2) setgid file.
Red Hat
rpm: fails to drop SUID/SGID bits on package removal
vendor_redhat·2010-06-01·CVSS 7.2
CVE-2005-4889 [HIGH] rpm: fails to drop SUID/SGID bits on package removal
rpm: fails to drop SUID/SGID bits on package removal
lib/fsm.c in RPM before 4.4.3 does not properly reset the metadata of an executable file during deletion of the file in an RPM package removal, which might allow local users to gain privileges by creating a hard link to a vulnerable (1) setuid or (2) setgid file, a related issue to CVE-2010-2059.
Red Hat
rpm: fails to drop POSIX ACLs on package upgrade or removal
vendor_redhat·2010-06-01·CVSS 7.2
CVE-2010-2199 [HIGH] rpm: fails to drop POSIX ACLs on package upgrade or removal
rpm: fails to drop POSIX ACLs on package upgrade or removal
lib/fsm.c in RPM 4.8.0 and earlier does not properly reset the metadata of an executable file during replacement of the file in an RPM package upgrade or deletion of the file in an RPM package removal, which might allow local users to bypass intended access restrictions by creating a hard link to a vulnerable file that has a POSIX ACL, a related issue to CVE-2010-2059.
Statement: We do not consider RPM's lack of removing POSIX ACLs to be security sensitive. Users cannot use POSIX ACLs to elevate their privileges; therefore, there is no need to clear them upon package upgrade or removal.
Debian
CVE-2010-2199: rpm - lib/fsm.c in RPM 4.8.0 and earlier does not properly reset the metadata of an ex...
vendor_debian·2010·CVSS 7.2
CVE-2010-2199 [HIGH] CVE-2010-2199: rpm - lib/fsm.c in RPM 4.8.0 and earlier does not properly reset the metadata of an ex...
lib/fsm.c in RPM 4.8.0 and earlier does not properly reset the metadata of an executable file during replacement of the file in an RPM package upgrade or deletion of the file in an RPM package removal, which might allow local users to bypass intended access restrictions by creating a hard link to a vulnerable file that has a POSIX ACL, a related issue to CVE-2010-2059.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
Debian
CVE-2010-2198: rpm - lib/fsm.c in RPM 4.8.0 and earlier does not properly reset the metadata of an ex...
vendor_debian·2010·CVSS 7.2
CVE-2010-2198 [HIGH] CVE-2010-2198: rpm - lib/fsm.c in RPM 4.8.0 and earlier does not properly reset the metadata of an ex...
lib/fsm.c in RPM 4.8.0 and earlier does not properly reset the metadata of an executable file during replacement of the file in an RPM package upgrade or deletion of the file in an RPM package removal, which might allow local users to gain privileges or bypass intended access restrictions by creating a hard link to a vulnerable file that has (1) POSIX file capabilities or (2) SELinux context information, a related issue to CVE-2010-2059.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
Debian
CVE-2010-2059: rpm - lib/fsm.c in RPM 4.8.0 and unspecified 4.7.x and 4.6.x versions, and RPM before ...
vendor_debian·2010·CVSS 7.2
CVE-2010-2059 [HIGH] CVE-2010-2059: rpm - lib/fsm.c in RPM 4.8.0 and unspecified 4.7.x and 4.6.x versions, and RPM before ...
lib/fsm.c in RPM 4.8.0 and unspecified 4.7.x and 4.6.x versions, and RPM before 4.4.3, does not properly reset the metadata of an executable file during replacement of the file in an RPM package upgrade, which might allow local users to gain privileges by creating a hard link to a vulnerable (1) setuid or (2) setgid file.
Scope: local
bookworm: resolved (fixed in 4.8.1-1)
bullseye: resolved (fixed in 4.8.1-1)
forky: resolved (fixed in 4.8.1-1)
sid: resolved (fixed in 4.8.1-1)
trixie: resolved (fixed in 4.8.1-1)
Debian
CVE-2005-4889: rpm - lib/fsm.c in RPM before 4.4.3 does not properly reset the metadata of an executa...
vendor_debian·2005·CVSS 7.2
CVE-2005-4889 [HIGH] CVE-2005-4889: rpm - lib/fsm.c in RPM before 4.4.3 does not properly reset the metadata of an executa...
lib/fsm.c in RPM before 4.4.3 does not properly reset the metadata of an executable file during deletion of the file in an RPM package removal, which might allow local users to gain privileges by creating a hard link to a vulnerable (1) setuid or (2) setgid file, a related issue to CVE-2010-2059.
Scope: local
bookworm: resolved (fixed in 4.7.0-1)
bullseye: resolved (fixed in 4.7.0-1)
forky: resolved (fixed in 4.7.0-1)
sid: resolved (fixed in 4.7.0-1)
trixie: resolved (fixed in 4.7.0-1)
Debian
CVE-2004-2768: dpkg - dpkg 1.9.21 does not properly reset the metadata of a file during replacement of...
vendor_debian·2004·CVSS 7.2
CVE-2004-2768 [HIGH] CVE-2004-2768: dpkg - dpkg 1.9.21 does not properly reset the metadata of a file during replacement of...
dpkg 1.9.21 does not properly reset the metadata of a file during replacement of the file in a package upgrade, which might allow local users to gain privileges by creating a hard link to a vulnerable (1) setuid file, (2) setgid file, or (3) device, a related issue to CVE-2010-2059.
Scope: local
bookworm: resolved (fixed in 1.10.19)
bullseye: resolved (fixed in 1.10.19)
forky: resolved (fixed in 1.10.19)
sid: resolved (fixed in 1.10.19)
trixie: resolved (fixed in 1.10.19)
GHSA
GHSA-fw46-vp2w-pvxq: lib/fsm
ghsa_unreviewed·2022-05-17·CVSS 7.2
CVE-2010-2198 [HIGH] GHSA-fw46-vp2w-pvxq: lib/fsm
lib/fsm.c in RPM 4.8.0 and earlier does not properly reset the metadata of an executable file during replacement of the file in an RPM package upgrade or deletion of the file in an RPM package removal, which might allow local users to gain privileges or bypass intended access restrictions by creating a hard link to a vulnerable file that has (1) POSIX file capabilities or (2) SELinux context information, a related issue to CVE-2010-2059.
GHSA
GHSA-7v29-vf8p-2rvp: lib/fsm
ghsa_unreviewed·2022-05-17·CVSS 7.2
CVE-2010-2199 [HIGH] GHSA-7v29-vf8p-2rvp: lib/fsm
lib/fsm.c in RPM 4.8.0 and earlier does not properly reset the metadata of an executable file during replacement of the file in an RPM package upgrade or deletion of the file in an RPM package removal, which might allow local users to bypass intended access restrictions by creating a hard link to a vulnerable file that has a POSIX ACL, a related issue to CVE-2010-2059.
GHSA
GHSA-f3f6-q22p-8fh5: lib/fsm
ghsa_unreviewed·2022-05-14
CVE-2010-2059 [HIGH] GHSA-f3f6-q22p-8fh5: lib/fsm
lib/fsm.c in RPM 4.8.0 and unspecified 4.7.x and 4.6.x versions, and RPM before 4.4.3, does not properly reset the metadata of an executable file during replacement of the file in an RPM package upgrade, which might allow local users to gain privileges by creating a hard link to a vulnerable (1) setuid or (2) setgid file.
GHSA
GHSA-pfqv-vjx4-pmxj: lib/fsm
ghsa_unreviewed·2022-05-01·CVSS 7.2
CVE-2005-4889 [HIGH] GHSA-pfqv-vjx4-pmxj: lib/fsm
lib/fsm.c in RPM before 4.4.3 does not properly reset the metadata of an executable file during deletion of the file in an RPM package removal, which might allow local users to gain privileges by creating a hard link to a vulnerable (1) setuid or (2) setgid file, a related issue to CVE-2010-2059.
GHSA
GHSA-qrp8-65v4-pc63: dpkg 1
ghsa_unreviewed·2022-04-29·CVSS 7.2
CVE-2004-2768 [HIGH] GHSA-qrp8-65v4-pc63: dpkg 1
dpkg 1.9.21 does not properly reset the metadata of a file during replacement of the file in a package upgrade, which might allow local users to gain privileges by creating a hard link to a vulnerable (1) setuid file, (2) setgid file, or (3) device, a related issue to CVE-2010-2059.
OSV
CVE-2010-2199: lib/fsm
osv·2010-06-08·CVSS 7.2
CVE-2010-2199 [HIGH] CVE-2010-2199: lib/fsm
lib/fsm.c in RPM 4.8.0 and earlier does not properly reset the metadata of an executable file during replacement of the file in an RPM package upgrade or deletion of the file in an RPM package removal, which might allow local users to bypass intended access restrictions by creating a hard link to a vulnerable file that has a POSIX ACL, a related issue to CVE-2010-2059.
OSV
CVE-2004-2768: dpkg 1
osv·2010-06-08·CVSS 7.2
CVE-2004-2768 [HIGH] CVE-2004-2768: dpkg 1
dpkg 1.9.21 does not properly reset the metadata of a file during replacement of the file in a package upgrade, which might allow local users to gain privileges by creating a hard link to a vulnerable (1) setuid file, (2) setgid file, or (3) device, a related issue to CVE-2010-2059.
OSV
CVE-2005-4889: lib/fsm
osv·2010-06-08·CVSS 7.2
CVE-2005-4889 [HIGH] CVE-2005-4889: lib/fsm
lib/fsm.c in RPM before 4.4.3 does not properly reset the metadata of an executable file during deletion of the file in an RPM package removal, which might allow local users to gain privileges by creating a hard link to a vulnerable (1) setuid or (2) setgid file, a related issue to CVE-2010-2059.
OSV
CVE-2010-2198: lib/fsm
osv·2010-06-08·CVSS 7.2
CVE-2010-2198 [HIGH] CVE-2010-2198: lib/fsm
lib/fsm.c in RPM 4.8.0 and earlier does not properly reset the metadata of an executable file during replacement of the file in an RPM package upgrade or deletion of the file in an RPM package removal, which might allow local users to gain privileges or bypass intended access restrictions by creating a hard link to a vulnerable file that has (1) POSIX file capabilities or (2) SELinux context information, a related issue to CVE-2010-2059.
OSV
CVE-2010-2059: lib/fsm
osv·2010-06-08·CVSS 7.2
CVE-2010-2059 [HIGH] CVE-2010-2059: lib/fsm
lib/fsm.c in RPM 4.8.0 and unspecified 4.7.x and 4.6.x versions, and RPM before 4.4.3, does not properly reset the metadata of an executable file during replacement of the file in an RPM package upgrade, which might allow local users to gain privileges by creating a hard link to a vulnerable (1) setuid or (2) setgid file.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2005-4889 rpm: fails to drop SUID/SGID bits on package removal
bugzilla·2010-08-20·CVSS 7.2
CVE-2005-4889 [HIGH] CVE-2005-4889 rpm: fails to drop SUID/SGID bits on package removal
CVE-2005-4889 rpm: fails to drop SUID/SGID bits on package removal
Common Vulnerabilities and Exposures assigned an identifier CVE-2005-4889 to the following vulnerability:
lib/fsm.c in RPM before 4.4.3 does not properly reset the metadata of an executable file during deletion of the file in an RPM package removal, which might allow local users to gain privileges by creating a hard link to a vulnerable (1) setuid or (2) setgid file, a related issue to CVE-2010-2059.
References:
https://bugzilla.redhat.com/show_bug.cgi?id=125517
https://bugzilla.redhat.com/show_bug.cgi?id=598775
http://xforce.iss.net/xforce/xfdb/59426
This issue was fixed in Fedora rpm some time ago via bug #125517. RPM versions in Red Hat Enterprise Linux 3 and 4 do not contain the fix and are affected.
Discussion:
T
Bugzilla
CVE-2010-2199 rpm: fails to drop POSIX ACLs on package upgrade or removal
bugzilla·2010-06-08·CVSS 7.2
CVE-2010-2199 [HIGH] CVE-2010-2199 rpm: fails to drop POSIX ACLs on package upgrade or removal
CVE-2010-2199 rpm: fails to drop POSIX ACLs on package upgrade or removal
Common Vulnerabilities and Exposures assigned an identifier CVE-2010-2199 to
the following vulnerability:
Name: CVE-2010-2199
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2199
Assigned: 20100608
Reference: CONFIRM: https://bugzilla.redhat.com/show_bug.cgi?id=125517
lib/fsm.c in RPM 4.8.0 and earlier does not properly reset the
metadata of an executable file during replacement of the file in an
RPM package upgrade or deletion of the file in an RPM package removal,
which might allow local users to bypass intended access restrictions
by creating a hard link to a vulnerable file that has a POSIX ACL, a
related issue to CVE-2010-2059.
See bug #598775 for an initial description and comments of this issu
Bugzilla
CVE-2010-2198 rpm: fails to drop POSIX file capabilities on package upgrade or removal
bugzilla·2010-06-08·CVSS 7.2
CVE-2010-2198 [HIGH] CVE-2010-2198 rpm: fails to drop POSIX file capabilities on package upgrade or removal
CVE-2010-2198 rpm: fails to drop POSIX file capabilities on package upgrade or removal
Common Vulnerabilities and Exposures assigned an identifier CVE-2010-2198 to
the following vulnerability:
Name: CVE-2010-2198
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2198
Assigned: 20100608
Reference: MLIST:[oss-security] 20100602 Re: CVE Request -- rpm -- Fails to remove the SUID/SGID bits on package upgrade (RH BZ#598775)
Reference: URL: http://www.openwall.com/lists/oss-security/2010/06/02/3
Reference: MLIST:[oss-security] 20100603 Re: CVE Request -- rpm -- Fails to remove the SUID/SGID bits on package upgrade (RH BZ#598775)
Reference: URL: http://marc.info/?l=oss-security&m=127559059928131&w=2
Reference: MLIST:[oss-security] 20100603 Re: CVE Request -- rpm -- Fails to remove the
Bugzilla
CVE-2010-2059 rpm: fails to drop SUID/SGID bits on package upgrade
bugzilla·2010-06-02·CVSS 7.2
CVE-2010-2059 [HIGH] CVE-2010-2059 rpm: fails to drop SUID/SGID bits on package upgrade
CVE-2010-2059 rpm: fails to drop SUID/SGID bits on package upgrade
Created attachment 418879
SRPM for testing this bug
Description of problem:
When RPM replaces an executable, it does not clear the setuid and setgid bits of the old file. Thus, if a user made a hard link to the old executable, he/she will still be able to run it with elevated privileges. This is bad if it was replaced because it had a vulnerability. The problem seems to occur only when executables are replaced, not when they are erased.
This is the same bug that was previously noted in dpkg:
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=225692
Version-Release number of selected component (if applicable):
rpm-4.8.0-14.fc13.x86_64
How reproducible:
Always
Steps to Reproduce:
1. Rebuild the attached SRPM twice, once w
http://distrib-coffee.ipsl.jussieu.fr/pub/mirrors/rpm/files/rpm/rpm-4.4/rpm-4.4.3.tar.gzhttp://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.htmlhttp://lists.vmware.com/pipermail/security-announce/2011/000126.htmlhttp://marc.info/?l=oss-security&m=127559059928131&w=2http://rpm.org/gitweb?p=rpm.git%3Ba=commit%3Bh=ca2d6b2b484f1501eafdde02e1688409340d2383http://secunia.com/advisories/40028http://www.mandriva.com/security/advisories?name=MDVSA-2010:180http://www.openwall.com/lists/oss-security/2010/06/02/2http://www.openwall.com/lists/oss-security/2010/06/02/3http://www.openwall.com/lists/oss-security/2010/06/03/5http://www.openwall.com/lists/oss-security/2010/06/04/1http://www.osvdb.org/65143http://www.redhat.com/support/errata/RHSA-2010-0679.htmlhttp://www.securityfocus.com/archive/1/516909/100/0/threadedhttp://www.vmware.com/security/advisories/VMSA-2011-0004.htmlhttp://www.vupen.com/english/advisories/2011/0606https://bugzilla.redhat.com/show_bug.cgi?id=125517https://bugzilla.redhat.com/show_bug.cgi?id=598775http://distrib-coffee.ipsl.jussieu.fr/pub/mirrors/rpm/files/rpm/rpm-4.4/rpm-4.4.3.tar.gzhttp://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.htmlhttp://lists.vmware.com/pipermail/security-announce/2011/000126.htmlhttp://marc.info/?l=oss-security&m=127559059928131&w=2http://rpm.org/gitweb?p=rpm.git%3Ba=commit%3Bh=ca2d6b2b484f1501eafdde02e1688409340d2383http://secunia.com/advisories/40028http://www.mandriva.com/security/advisories?name=MDVSA-2010:180http://www.openwall.com/lists/oss-security/2010/06/02/2http://www.openwall.com/lists/oss-security/2010/06/02/3http://www.openwall.com/lists/oss-security/2010/06/03/5http://www.openwall.com/lists/oss-security/2010/06/04/1http://www.osvdb.org/65143http://www.redhat.com/support/errata/RHSA-2010-0679.htmlhttp://www.securityfocus.com/archive/1/516909/100/0/threadedhttp://www.vmware.com/security/advisories/VMSA-2011-0004.htmlhttp://www.vupen.com/english/advisories/2011/0606https://bugzilla.redhat.com/show_bug.cgi?id=125517https://bugzilla.redhat.com/show_bug.cgi?id=598775
2010-06-08
Published