CVE-2021-35939 Vulnerability Details

  /     /     /  

CVE-2021-35939 Metadata Quick Info

CVE Published: 26/08/2022 | CVE Updated: 04/08/2024 | CVE Year: 2021
Source: redhat | Vendor: n/a | Product: RPM
Status : PUBLISHED

CVE-2021-35939 Description

It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to be created. A local unprivileged user who owns another ancestor directory could potentially use this flaw to gain root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-59
CWE Name: CWE-59 - Improper Link Resolution Before File Access ( Link Following )
Source: n/a

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).