Vulnerabilities > CVE-2000-0948 - Unspecified vulnerability in Gnome Gnorpm
Attack vector
LOCAL Attack complexity
LOW Privileges required
NONE Confidentiality impact
COMPLETE Integrity impact
COMPLETE Availability impact
COMPLETE Summary
GnoRPM before 0.95 allows local users to modify arbitrary files via a symlink attack.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Nessus
NASL family | Mandriva Local Security Checks |
NASL id | MANDRAKE_MDKSA-2000-055.NASL |
description | Versions of GnoRPM prior to 0.95 used files in the /tmp directory in an insecure manner. If GnoRPM is run as root, a local user can exploit this behaviour to trick GnoRPM into writing to arbitrary files anywhere on the system. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 61845 |
published | 2012-09-06 |
reporter | This script is Copyright (C) 2012-2019 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/61845 |
title | Mandrake Linux Security Advisory : gnorpm (MDKSA-2000:055) |
code |
|
Redhat
advisories |
|
References
- http://archives.neohapsis.com/archives/bugtraq/2000-10/0043.html
- http://archives.neohapsis.com/archives/bugtraq/2000-10/0184.html
- http://www.linux-mandrake.com/en/security/MDKSA-2000-055.php3?dis=7.0
- http://www.redhat.com/support/errata/RHSA-2000-072.html
- http://www.securityfocus.com/archive/1/136866
- http://www.securityfocus.com/bid/1761
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5317