Vulnerability Details CVE-2010-2197
rpmbuild in RPM 4.8.0 and earlier does not properly parse the syntax of spec files, which allows user-assisted remote attackers to remove home directories via vectors involving a ;~ (semicolon tilde) sequence in a Name tag.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 61.7%
CVSS Severity
CVSS v2 Score 5.8
Products affected by CVE-2010-2197
-
-
-
-
-
-
-
cpe:2.3:a:rpm:rpm:1.4.2/a
-
-
-
-
-
-
cpe:2.3:a:rpm:rpm:2..4.10
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
cpe:2.3:a:rpm:rpm:2.2.3.10
-
cpe:2.3:a:rpm:rpm:2.2.3.11
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
cpe:2.3:a:rpm:rpm:4.4.2.1
-
cpe:2.3:a:rpm:rpm:4.4.2.2
-
cpe:2.3:a:rpm:rpm:4.4.2.3
-
-
-
-
-
-
-