CVE-2004-2133: Medium severity cvsup cvsup vulnerability
Certain third-party packages for CVSup 16.1h, such as SuSE Linux, contain untrusted paths in the ELF RPATH fields of certain executables, which could allow local users to execute arbitrary code by causing cvsup to link against malicious libraries that are created in world-writable directories such as /usr/src/packages.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-2133?
CVE-2004-2133 is classified as a medium severity vulnerability.
How do I fix CVE-2004-2133?
To fix CVE-2004-2133, avoid using untrusted paths in the RPATH fields and ensure libraries are not placed in world-writable directories.
Who is affected by CVE-2004-2133?
CVE-2004-2133 affects local users of certain third-party CVSup packages, particularly those on SuSE Linux.
What can an attacker do with CVE-2004-2133?
An attacker can execute arbitrary code by exploiting the untrusted paths in the ELF RPATH fields.
Is CVE-2004-2133 related to specific versions of CVSup?
Yes, CVE-2004-2133 specifically affects CVSup version 16.1h in certain RPM packages.