CVE-2010-4226
Severity CVSS v4.0:
Pending analysis
Type:
CWE-59
Link Following
Publication date:
06/02/2014
Last modified:
09/06/2025
Description
cpio, as used in build 2007.05.10, 2010.07.28, and possibly other versions, allows remote attackers to overwrite arbitrary files via a symlink within an RPM package archive.
Impact
Base Score 3.x
7.20
Severity 3.x
HIGH
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:gnu:cpio:*:*:*:*:*:*:*:* | ||
cpe:2.3:o:opensuse:opensuse:2007.05.10:*:*:*:*:*:*:* | ||
cpe:2.3:o:opensuse:opensuse:2010.07.28:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://lists.opensuse.org/opensuse-security-announce/2011-04/msg00000.html
- http://lists.opensuse.org/opensuse-updates/2011-03/msg00008.html
- http://support.novell.com/security/cve/CVE-2010-4226.html
- https://bugzilla.novell.com/show_bug.cgi?id=665768
- http://lists.opensuse.org/opensuse-security-announce/2011-04/msg00000.html
- http://lists.opensuse.org/opensuse-updates/2011-03/msg00008.html
- http://support.novell.com/security/cve/CVE-2010-4226.html
- https://bugzilla.novell.com/show_bug.cgi?id=665768