Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jgh7-mh2q-3476

Опубликовано: 05 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 5.5

Описание

A flaw was found in the RPM Package Manager (RPM). A local user could be affected by a heap buffer overflow vulnerability when processing a specially crafted NDB database file. This issue arises from an error in how RPM handles certain calculations during file parsing, leading to an incorrect memory allocation. An attacker could leverage this to cause a denial of service, making the system unavailable.

A flaw was found in the RPM Package Manager (RPM). A local user could be affected by a heap buffer overflow vulnerability when processing a specially crafted NDB database file. This issue arises from an error in how RPM handles certain calculations during file parsing, leading to an incorrect memory allocation. An attacker could leverage this to cause a denial of service, making the system unavailable.

EPSS

Процентиль: 3%
0.00135
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-190

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 1 месяца назад

[Unknown description]

CVSS3: 5.5
redhat
2 месяца назад

A flaw was found in the RPM Package Manager (RPM). A local user could be affected by a heap buffer overflow vulnerability when processing a specially crafted NDB database file. This issue arises from an error in how RPM handles certain calculations during file parsing, leading to an incorrect memory allocation. An attacker could leverage this to cause a denial of service, making the system unavailable.

CVSS3: 5.5
nvd
3 дня назад

A flaw was found in the RPM Package Manager (RPM). A local user could be affected by a heap buffer overflow vulnerability when processing a specially crafted NDB database file. This issue arises from an error in how RPM handles certain calculations during file parsing, leading to an incorrect memory allocation. An attacker could leverage this to cause a denial of service, making the system unavailable.

CVSS3: 5.5
debian
3 дня назад

A flaw was found in the RPM Package Manager (RPM). A local user could ...

EPSS

Процентиль: 3%
0.00135
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-190