Описание
ELSA-2011-1349: rpm security update (IMPORTANT)
[4.8.0-16.1]
- fix CVE-2011-3378 (#742154)
Обновленные пакеты
Oracle Linux 5
Oracle Linux ia64
popt
1.10.2.3-22.0.1.el5_7.2
rpm
4.4.2.3-22.0.1.el5_7.2
rpm-apidocs
4.4.2.3-22.0.1.el5_7.2
rpm-build
4.4.2.3-22.0.1.el5_7.2
rpm-devel
4.4.2.3-22.0.1.el5_7.2
rpm-libs
4.4.2.3-22.0.1.el5_7.2
rpm-python
4.4.2.3-22.0.1.el5_7.2
Oracle Linux x86_64
popt
1.10.2.3-22.0.1.el5_7.2
rpm
4.4.2.3-22.0.1.el5_7.2
rpm-apidocs
4.4.2.3-22.0.1.el5_7.2
rpm-build
4.4.2.3-22.0.1.el5_7.2
rpm-devel
4.4.2.3-22.0.1.el5_7.2
rpm-libs
4.4.2.3-22.0.1.el5_7.2
rpm-python
4.4.2.3-22.0.1.el5_7.2
Oracle Linux i386
popt
1.10.2.3-22.0.1.el5_7.2
rpm
4.4.2.3-22.0.1.el5_7.2
rpm-apidocs
4.4.2.3-22.0.1.el5_7.2
rpm-build
4.4.2.3-22.0.1.el5_7.2
rpm-devel
4.4.2.3-22.0.1.el5_7.2
rpm-libs
4.4.2.3-22.0.1.el5_7.2
rpm-python
4.4.2.3-22.0.1.el5_7.2
Oracle Linux 6
Oracle Linux x86_64
rpm
4.8.0-16.el6_1.1
rpm-apidocs
4.8.0-16.el6_1.1
rpm-build
4.8.0-16.el6_1.1
rpm-cron
4.8.0-16.el6_1.1
rpm-devel
4.8.0-16.el6_1.1
rpm-libs
4.8.0-16.el6_1.1
rpm-python
4.8.0-16.el6_1.1
Oracle Linux i686
rpm
4.8.0-16.el6_1.1
rpm-apidocs
4.8.0-16.el6_1.1
rpm-build
4.8.0-16.el6_1.1
rpm-cron
4.8.0-16.el6_1.1
rpm-devel
4.8.0-16.el6_1.1
rpm-libs
4.8.0-16.el6_1.1
rpm-python
4.8.0-16.el6_1.1
Связанные CVE
Связанные уязвимости
RPM 4.4.x through 4.9.x, probably before 4.9.1.2, allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via an rpm package with crafted headers and offsets that are not properly handled when a package is queried or installed, related to (1) the regionSwab function, (2) the headerLoad function, and (3) multiple functions in rpmio/rpmpgp.c.
RPM 4.4.x through 4.9.x, probably before 4.9.1.2, allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via an rpm package with crafted headers and offsets that are not properly handled when a package is queried or installed, related to (1) the regionSwab function, (2) the headerLoad function, and (3) multiple functions in rpmio/rpmpgp.c.
RPM 4.4.x through 4.9.x, probably before 4.9.1.2, allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via an rpm package with crafted headers and offsets that are not properly handled when a package is queried or installed, related to (1) the regionSwab function, (2) the headerLoad function, and (3) multiple functions in rpmio/rpmpgp.c.
RPM 4.4.x through 4.9.x, probably before 4.9.1.2, allows remote attack ...
RPM 4.4.x through 4.9.x, probably before 4.9.1.2, allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via an rpm package with crafted headers and offsets that are not properly handled when a package is queried or installed, related to (1) the regionSwab function, (2) the headerLoad function, and (3) multiple functions in rpmio/rpmpgp.c.