Описание
The headerVerifyInfo function in lib/header.c in RPM before 4.9.1.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a negative value in a region offset of a package header, which is not properly handled in a numeric range comparison.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux Extended Update Support 5.3 | rpm | Affected | ||
Red Hat Enterprise Linux 3 Extended Lifecycle Support | rpm | Fixed | RHSA-2012:0451 | 03.04.2012 |
Red Hat Enterprise Linux 4 Extended Lifecycle Support | rpm | Fixed | RHSA-2012:0451 | 03.04.2012 |
Red Hat Enterprise Linux 5 | rpm | Fixed | RHSA-2012:0451 | 03.04.2012 |
Red Hat Enterprise Linux 5.3 Long Life | rpm | Fixed | RHSA-2012:0451 | 03.04.2012 |
Red Hat Enterprise Linux 5.6 EUS - Server Only | rpm | Fixed | RHSA-2012:0451 | 03.04.2012 |
Red Hat Enterprise Linux 6 | rpm | Fixed | RHSA-2012:0451 | 03.04.2012 |
Red Hat Enterprise Linux 6.0 EUS - Server Only | rpm | Fixed | RHSA-2012:0451 | 03.04.2012 |
Red Hat Enterprise Linux 6.1 EUS - Server Only | rpm | Fixed | RHSA-2012:0451 | 03.04.2012 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.6 High
CVSS2
Связанные уязвимости
The headerVerifyInfo function in lib/header.c in RPM before 4.9.1.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a negative value in a region offset of a package header, which is not properly handled in a numeric range comparison.
The headerVerifyInfo function in lib/header.c in RPM before 4.9.1.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a negative value in a region offset of a package header, which is not properly handled in a numeric range comparison.
The headerVerifyInfo function in lib/header.c in RPM before 4.9.1.3 al ...
The headerVerifyInfo function in lib/header.c in RPM before 4.9.1.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a negative value in a region offset of a package header, which is not properly handled in a numeric range comparison.
EPSS
7.6 High
CVSS2