CVE-2010-2197
published 2010-06-08CVE-2010-2197: rpmbuild in RPM 4.8.0 and earlier does not properly parse the syntax of spec files, which allows user-assisted remote attackers to remove home directories via…
PriorityP424medium5.8CVSS 2.0
AVNACMAuNCNIPAP
EPSS
1.00%
58.8th percentile
rpmbuild in RPM 4.8.0 and earlier does not properly parse the syntax of spec files, which allows user-assisted remote attackers to remove home directories via vectors involving a ;~ (semicolon tilde) sequence in a Name tag.
Affected
98 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | rpm | < rpm 4.8.1-1 (bookworm) | rpm 4.8.1-1 (bookworm) |
| rpm | rpm | <= 4.8.0 | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
CVSS provenance
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:P
osv5.8MEDIUM
vendor_debian5.8LOW
vendor_redhat5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
rpm: rpmbuild does not properly parse syntax of spec files
vendor_redhat·2010-06-08·CVSS 5.8
CVE-2010-2197 [MEDIUM] rpm: rpmbuild does not properly parse syntax of spec files
rpm: rpmbuild does not properly parse syntax of spec files
rpmbuild in RPM 4.8.0 and earlier does not properly parse the syntax of spec files, which allows user-assisted remote attackers to remove home directories via vectors involving a ;~ (semicolon tilde) sequence in a Name tag.
Statement: We do not consider this to be a security issue as it does not introduce any additional risk in using untrusted RPM .spec files. RPM .spec files can do a lot of things, regardless of how rpmbuild parses the syntax, because certain sections of the .spec file (%prep, %build, etc.) are treated as shell scripts. Because of the ability to easily include malicious commands anywhere, an untrusted .spec file should be carefully examined prior to building, the same as if you were to download and execute an un
Debian
CVE-2010-2197: rpm - rpmbuild in RPM 4.8.0 and earlier does not properly parse the syntax of spec fil...
vendor_debian·2010·CVSS 5.8
CVE-2010-2197 [MEDIUM] CVE-2010-2197: rpm - rpmbuild in RPM 4.8.0 and earlier does not properly parse the syntax of spec fil...
rpmbuild in RPM 4.8.0 and earlier does not properly parse the syntax of spec files, which allows user-assisted remote attackers to remove home directories via vectors involving a ;~ (semicolon tilde) sequence in a Name tag.
Scope: local
bookworm: resolved (fixed in 4.8.1-1)
bullseye: resolved (fixed in 4.8.1-1)
forky: resolved (fixed in 4.8.1-1)
sid: resolved (fixed in 4.8.1-1)
trixie: resolved (fixed in 4.8.1-1)
GHSA
GHSA-6gj2-w23f-chf3: rpmbuild in RPM 4
ghsa_unreviewed·2022-05-17
CVE-2010-2197 [MEDIUM] GHSA-6gj2-w23f-chf3: rpmbuild in RPM 4
rpmbuild in RPM 4.8.0 and earlier does not properly parse the syntax of spec files, which allows user-assisted remote attackers to remove home directories via vectors involving a ;~ (semicolon tilde) sequence in a Name tag.
OSV
CVE-2010-2197: rpmbuild in RPM 4
osv·2010-06-08·CVSS 5.8
CVE-2010-2197 [MEDIUM] CVE-2010-2197: rpmbuild in RPM 4
rpmbuild in RPM 4.8.0 and earlier does not properly parse the syntax of spec files, which allows user-assisted remote attackers to remove home directories via vectors involving a ;~ (semicolon tilde) sequence in a Name tag.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-2197 rpm: rpmbuild does not properly parse syntax of spec files
bugzilla·2010-06-12·CVSS 5.8
CVE-2010-2197 [MEDIUM] CVE-2010-2197 rpm: rpmbuild does not properly parse syntax of spec files
CVE-2010-2197 rpm: rpmbuild does not properly parse syntax of spec files
Common Vulnerabilities and Exposures assigned an identifier CVE-2010-2197 to
the following vulnerability:
Name: CVE-2010-2197
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2197
Assigned: 20100608
Reference: CONFIRM: https://bugzilla.redhat.com/show_bug.cgi?id=125517
rpmbuild in RPM 4.8.0 and earlier does not properly parse the syntax
of spec files, which allows user-assisted remote attackers to remove
home directories via vectors involving a ;~ (semicolon tilde) sequence
in a Name tag.
Discussion:
This was originally reported here: https://bugzilla.redhat.com/show_bug.cgi?id=125517#c13
I don't believe we can consider this a flaw. There are easier ways to remove a home directory in the spec file its
Bugzilla
CVE-2010-2199 rpm: fails to drop POSIX ACLs on package upgrade or removal
bugzilla·2010-06-08·CVSS 7.2
CVE-2010-2199 [HIGH] CVE-2010-2199 rpm: fails to drop POSIX ACLs on package upgrade or removal
CVE-2010-2199 rpm: fails to drop POSIX ACLs on package upgrade or removal
Common Vulnerabilities and Exposures assigned an identifier CVE-2010-2199 to
the following vulnerability:
Name: CVE-2010-2199
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2199
Assigned: 20100608
Reference: CONFIRM: https://bugzilla.redhat.com/show_bug.cgi?id=125517
lib/fsm.c in RPM 4.8.0 and earlier does not properly reset the
metadata of an executable file during replacement of the file in an
RPM package upgrade or deletion of the file in an RPM package removal,
which might allow local users to bypass intended access restrictions
by creating a hard link to a vulnerable file that has a POSIX ACL, a
related issue to CVE-2010-2059.
See bug #598775 for an initial description and comments of this issu
2010-06-08
Published