dpkg 1.9.21 does not properly reset the metadata of a file during replacement of the file in a package upgrade, which might allow local users to gain privileges by creating a hard link to a vulnerable (1) setuid file, (2) setgid file, or (3) device, a related issue to CVE-2010-2059.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2010-06-08T18:00:00

Updated: 2024-08-08T01:36:25.375Z

Reserved: 2010-06-08T00:00:00

Link: CVE-2004-2768

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2010-06-08T18:30:07.740

Modified: 2017-08-17T01:29:01.973

Link: CVE-2004-2768

cve-icon Redhat

No data.