CVE-2004-2133
Status: ModifiedMedium (4.6)—
Certain third-party packages for CVSup 16.1h, such as SuSE Linux, contain untrusted paths in the ELF RPATH fields of certain executables, which could allow local users to execute arbitrary code by causing cvsup to link against malicious libraries that are created in world-writable directories such as /usr/src/packages.
CVSS
- Version: 2.0
- Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P
- Base score: 4.6
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.61%
- Percentile among all scored CVEs: 47
- Score date: 10/5/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- NVD-CWE-Other
References
- http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0025.html
- http://marc.info/?l=bugtraq&m=107539776002450&w=2
- http://www.securityfocus.com/bid/9523
- https://exchange.xforce.ibmcloud.com/vulnerabilities/14994
- http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0025.html
- http://marc.info/?l=bugtraq&m=107539776002450&w=2
- http://www.securityfocus.com/bid/9523
- https://exchange.xforce.ibmcloud.com/vulnerabilities/14994
Raw JSON (NVD)
Show
{
"id": "CVE-2004-2133",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.6,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.9,
"obtainUserPrivilege": true,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2004-01-29T05:00:00.000",
"references": [
{
"url": "http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0025.html",
"tags": [
"Exploit",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://marc.info/?l=bugtraq&m=107539776002450&w=2",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/9523",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/14994",
"source": "cve@mitre.org"
},
{
"url": "http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0025.html",
"tags": [
"Exploit",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://marc.info/?l=bugtraq&m=107539776002450&w=2",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/9523",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/14994",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Certain third-party packages for CVSup 16.1h, such as SuSE Linux, contain untrusted paths in the ELF RPATH fields of certain executables, which could allow local users to execute arbitrary code by causing cvsup to link against malicious libraries that are created in world-writable directories such as /usr/src/packages."
}
],
"lastModified": "2026-06-16T22:09:04.503",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:cvsup:cvsup:cvsup-16.1h-2.i386.rpm:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "07629432-BEC4-442C-929B-5F11AC3A7C37"
},
{
"criteria": "cpe:2.3:a:cvsup:cvsup:cvsup-16.1h-36.i586.rpm:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1F9762EE-77FF-4F24-88F3-C21F10038A2D"
},
{
"criteria": "cpe:2.3:a:cvsup:cvsup:cvsup-16.1h-43.i586.rpm:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B93F581B-72AB-43CB-BF54-C1AB43E93248"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}