Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2012-6088

Опубликовано: 18 янв. 2013
Источник: debian
EPSS Низкий

Описание

The rpmpkgRead function in lib/package.c in RPM 4.10.x before 4.10.2 does not return an error code in certain situations involving an "unparseable signature," which allows remote attackers to bypass RPM signature checks via a crafted package.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
rpmfixed4.10.1-2.1package
rpmnot-affectedsqueezepackage
rpmfixed4.10.0-5+deb7u1wheezypackage

EPSS

Процентиль: 67%
0.00528
Низкий

Связанные уязвимости

ubuntu
около 13 лет назад

The rpmpkgRead function in lib/package.c in RPM 4.10.x before 4.10.2 does not return an error code in certain situations involving an "unparseable signature," which allows remote attackers to bypass RPM signature checks via a crafted package.

CVSS3: 6.2
redhat
около 3 лет назад

The rpmpkgRead function in lib/package.c in RPM 4.10.x before 4.10.2 does not return an error code in certain situations involving an "unparseable signature," which allows remote attackers to bypass RPM signature checks via a crafted package.

nvd
около 13 лет назад

The rpmpkgRead function in lib/package.c in RPM 4.10.x before 4.10.2 does not return an error code in certain situations involving an "unparseable signature," which allows remote attackers to bypass RPM signature checks via a crafted package.

github
почти 4 года назад

The rpmpkgRead function in lib/package.c in RPM 4.10.x before 4.10.2 does not return an error code in certain situations involving an "unparseable signature," which allows remote attackers to bypass RPM signature checks via a crafted package.

EPSS

Процентиль: 67%
0.00528
Низкий
Уязвимость CVE-2012-6088