Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v3v4-hffr-vr89

Опубликовано: 04 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The headerLoad function in lib/header.c in RPM before 4.9.1.3 does not properly validate region tags, which allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large region size in a package header.

The headerLoad function in lib/header.c in RPM before 4.9.1.3 does not properly validate region tags, which allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large region size in a package header.

EPSS

Процентиль: 91%
0.06568
Низкий

Дефекты

CWE-20

Связанные уязвимости

ubuntu
около 13 лет назад

The headerLoad function in lib/header.c in RPM before 4.9.1.3 does not properly validate region tags, which allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large region size in a package header.

redhat
больше 13 лет назад

The headerLoad function in lib/header.c in RPM before 4.9.1.3 does not properly validate region tags, which allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large region size in a package header.

nvd
около 13 лет назад

The headerLoad function in lib/header.c in RPM before 4.9.1.3 does not properly validate region tags, which allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large region size in a package header.

debian
около 13 лет назад

The headerLoad function in lib/header.c in RPM before 4.9.1.3 does not ...

oracle-oval
больше 13 лет назад

ELSA-2012-0451: rpm security update (IMPORTANT)

EPSS

Процентиль: 91%
0.06568
Низкий

Дефекты

CWE-20