← Back

CVE-2004-2133

nvd nist
Published: Jan 29, 2004Modified: Apr 16, 2026

JSON object

Loading...
4.6
Vector
AV:L/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 3.9 / Impact: 6.4
Source: NVD

Description

Certain third-party packages for CVSup 16.1h, such as SuSE Linux, contain untrusted paths in the ELF RPATH fields of certain executables, which could allow local users to execute arbitrary code by causing cvsup to link against malicious libraries that are created in world-writable directories such as /usr/src/packages.

Affected (3)

Products: Cvsup: Cvsup
1 product
Cvsup
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Cvsup
Version cvsup-16.1h-2.i386.rpm
Version cvsup-16.1h-36.i586.rpm
Version cvsup-16.1h-43.i586.rpm

References (8)

Source: cve@mitre.org
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.