Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2012-0060

Опубликовано: 03 апр. 2012
Источник: redhat
CVSS2: 7.6
EPSS Низкий

Описание

RPM before 4.9.1.3 does not properly validate region tags, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an invalid region tag in a package header to the (1) headerLoad, (2) rpmReadSignature, or (3) headerVerify function.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux Extended Update Support 5.3rpmAffected
Red Hat Enterprise Linux 3 Extended Lifecycle SupportrpmFixedRHSA-2012:045103.04.2012
Red Hat Enterprise Linux 4 Extended Lifecycle SupportrpmFixedRHSA-2012:045103.04.2012
Red Hat Enterprise Linux 5rpmFixedRHSA-2012:045103.04.2012
Red Hat Enterprise Linux 5.3 Long LiferpmFixedRHSA-2012:045103.04.2012
Red Hat Enterprise Linux 5.6 EUS - Server OnlyrpmFixedRHSA-2012:045103.04.2012
Red Hat Enterprise Linux 6rpmFixedRHSA-2012:045103.04.2012
Red Hat Enterprise Linux 6.0 EUS - Server OnlyrpmFixedRHSA-2012:045103.04.2012
Red Hat Enterprise Linux 6.1 EUS - Server OnlyrpmFixedRHSA-2012:045103.04.2012

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-228->CWE-119
https://bugzilla.redhat.com/show_bug.cgi?id=744858rpm: insufficient validation of region tags

EPSS

Процентиль: 91%
0.06486
Низкий

7.6 High

CVSS2

Связанные уязвимости

ubuntu
около 13 лет назад

RPM before 4.9.1.3 does not properly validate region tags, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an invalid region tag in a package header to the (1) headerLoad, (2) rpmReadSignature, or (3) headerVerify function.

nvd
около 13 лет назад

RPM before 4.9.1.3 does not properly validate region tags, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an invalid region tag in a package header to the (1) headerLoad, (2) rpmReadSignature, or (3) headerVerify function.

debian
около 13 лет назад

RPM before 4.9.1.3 does not properly validate region tags, which allow ...

github
больше 3 лет назад

RPM before 4.9.1.3 does not properly validate region tags, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an invalid region tag in a package header to the (1) headerLoad, (2) rpmReadSignature, or (3) headerVerify function.

oracle-oval
больше 13 лет назад

ELSA-2012-0451: rpm security update (IMPORTANT)

EPSS

Процентиль: 91%
0.06486
Низкий

7.6 High

CVSS2