cbcvebase.
CVE-2010-2197
published 2010-06-08

CVE-2010-2197: rpmbuild in RPM 4.8.0 and earlier does not properly parse the syntax of spec files, which allows user-assisted remote attackers to remove home directories via…

PriorityP424medium5.8CVSS 2.0
AVNACMAuNCNIPAP
EPSS
1.00%
58.8th percentile
rpmbuild in RPM 4.8.0 and earlier does not properly parse the syntax of spec files, which allows user-assisted remote attackers to remove home directories via vectors involving a ;~ (semicolon tilde) sequence in a Name tag.

Affected

98 ranges· showing 25
VendorProductVersion rangeFixed in
debianrpm< rpm 4.8.1-1 (bookworm)rpm 4.8.1-1 (bookworm)
rpmrpm<= 4.8.0
rpmrpm
rpmrpm
rpmrpm
rpmrpm
rpmrpm
rpmrpm
rpmrpm
rpmrpm
rpmrpm
rpmrpm
rpmrpm
rpmrpm
rpmrpm
rpmrpm
rpmrpm
rpmrpm
rpmrpm
rpmrpm
rpmrpm
rpmrpm
rpmrpm
rpmrpm
rpmrpm

CVSS provenance

nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:P
osv5.8MEDIUM
vendor_debian5.8LOW
vendor_redhat5.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.