Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-8118

Опубликовано: 09 дек. 2014
Источник: redhat
CVSS2: 7.6
EPSS Низкий

Описание

Integer overflow in RPM 4.12 and earlier allows remote attackers to execute arbitrary code via a crafted CPIO header in the payload section of an RPM file, which triggers a stack-based buffer overflow.

Отчет

This issue does not affect the version of rpm package as shipped with Red Hat Enterprise Linux 5 and 6.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 4rpmNot affected
Red Hat Enterprise Linux 5rpmNot affected
Red Hat Enterprise Linux 6rpmNot affected
Red Hat Enterprise Linux 7rpmFixedRHSA-2014:197609.12.2014

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=1168715rpm: integer overflow and stack overflow in CPIO header parsing

EPSS

Процентиль: 94%
0.07611
Низкий

7.6 High

CVSS2

Связанные уязвимости

ubuntu
больше 11 лет назад

Integer overflow in RPM 4.12 and earlier allows remote attackers to execute arbitrary code via a crafted CPIO header in the payload section of an RPM file, which triggers a stack-based buffer overflow.

nvd
больше 11 лет назад

Integer overflow in RPM 4.12 and earlier allows remote attackers to execute arbitrary code via a crafted CPIO header in the payload section of an RPM file, which triggers a stack-based buffer overflow.

debian
больше 11 лет назад

Integer overflow in RPM 4.12 and earlier allows remote attackers to ex ...

github
около 4 лет назад

Integer overflow in RPM 4.12 and earlier allows remote attackers to execute arbitrary code via a crafted CPIO header in the payload section of an RPM file, which triggers a stack-based buffer overflow.

oracle-oval
больше 11 лет назад

ELSA-2014-1976: rpm security update (IMPORTANT)

EPSS

Процентиль: 94%
0.07611
Низкий

7.6 High

CVSS2