A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-04T00:40:47.458Z
Reserved: 2021-06-29T00:00:00
Link: CVE-2021-35938

No data.

Status : Modified
Published: 2022-08-25T20:15:09.307
Modified: 2024-11-21T06:12:47.313
Link: CVE-2021-35938
