CVE-2010-2197
EPSS 0.43%Published: 6/8/2010Modified: 4/28/2026
Also known as:DEBIAN-CVE-2010-2197
Description
rpmbuild in RPM 4.8.0 and earlier does not properly parse the syntax of spec files, which allows user-assisted remote attackers to remove home directories via vectors involving a ;~ (semicolon tilde) sequence in a Name tag.
Affected packages (1)
- Debian/rpmfrom 0, < 4.8.1-1