Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qww5-w98g-66q7

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Race condition in RPM 4.11.1 and earlier allows remote attackers to execute arbitrary code via a crafted RPM file whose installation extracts the contents to temporary files before validating the signature, as demonstrated by installing a file in the /etc/cron.d directory.

Race condition in RPM 4.11.1 and earlier allows remote attackers to execute arbitrary code via a crafted RPM file whose installation extracts the contents to temporary files before validating the signature, as demonstrated by installing a file in the /etc/cron.d directory.

EPSS

Процентиль: 91%
0.06749
Низкий

Дефекты

CWE-74

Связанные уязвимости

ubuntu
больше 10 лет назад

Race condition in RPM 4.11.1 and earlier allows remote attackers to execute arbitrary code via a crafted RPM file whose installation extracts the contents to temporary files before validating the signature, as demonstrated by installing a file in the /etc/cron.d directory.

redhat
больше 10 лет назад

Race condition in RPM 4.11.1 and earlier allows remote attackers to execute arbitrary code via a crafted RPM file whose installation extracts the contents to temporary files before validating the signature, as demonstrated by installing a file in the /etc/cron.d directory.

nvd
больше 10 лет назад

Race condition in RPM 4.11.1 and earlier allows remote attackers to execute arbitrary code via a crafted RPM file whose installation extracts the contents to temporary files before validating the signature, as demonstrated by installing a file in the /etc/cron.d directory.

debian
больше 10 лет назад

Race condition in RPM 4.11.1 and earlier allows remote attackers to ex ...

oracle-oval
больше 10 лет назад

ELSA-2014-1974: rpm security update (IMPORTANT)

EPSS

Процентиль: 91%
0.06749
Низкий

Дефекты

CWE-74