Total vulnerabilities in the database
A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Software | From | Fixed in |
---|---|---|
rpm / rpm | - | 4.18.0 |
fedoraproject / fedora | 34 | 34.x |
redhat / enterprise_linux | 7.0 | 7.0.x |
redhat / enterprise_linux | 8.0 | 8.0.x |
redhat / enterprise_linux | 9.0 | 9.0.x |