CVE-2004-2768: High severity Debian Dpkg vulnerability
Published Jun 8, 2010
·Updated
dpkg 1.9.21 does not properly reset the metadata of a file during replacement of the file in a package upgrade, which might allow local users to gain privileges by creating a hard link to a vulnerable (1) setuid file, (2) setgid file, or (3) device, a related issue to CVE-2010-2059.
Affected Software
1 affected component
Debian Dpkg=1.9.21
Event History
Jun 8, 2010
CVE Published
06:30 PM
Data Sourced
via NVD·06:30 PM
DescriptionSeverityWeaknessAffected Software
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-2768?
CVE-2004-2768 is classified as a local privilege escalation vulnerability.
2
How do I fix CVE-2004-2768?
To fix CVE-2004-2768, users should upgrade dpkg to a version later than 1.9.21.
3
What versions of dpkg are affected by CVE-2004-2768?
CVE-2004-2768 affects dpkg version 1.9.21.
4
Who can exploit CVE-2004-2768?
Local users can exploit CVE-2004-2768 by creating hard links to vulnerable setuid or setgid files.
5
What can happen if CVE-2004-2768 is successfully exploited?
If successfully exploited, CVE-2004-2768 may allow local users to gain elevated privileges on the system.