Описание
A command injection vulnerability was discovered in the rpmuncompress utility of RPM. When extracting certain archive formats (ZIP, 7z, GEM) to a specified destination directory, the tool inserts the archive's top-level folder name into a shell command without properly sanitizing it. A specially crafted archive containing shell metacharacters in its folder name can execute arbitrary commands as the user running the extraction.
Отчет
This affects RPM source-preparation workflows, posing a risk in build environments. Standard tar extraction is not affected.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Pen Drive Powered by Red Hat Lightspeed | pen-drive/pen-drive-scanner-rhel9 | Under investigation | ||
| Red Hat build of Quarkus Native builder | rpm | Under investigation | ||
| Red Hat Enterprise Linux 10 | rpm | Under investigation | ||
| Red Hat Enterprise Linux 10 | rust-bootupd | Under investigation | ||
| Red Hat Enterprise Linux 6 | rpm | Under investigation | ||
| Red Hat Enterprise Linux 7 | rpm | Under investigation | ||
| Red Hat Enterprise Linux 8 | rpm | Under investigation | ||
| Red Hat Enterprise Linux 9 | rpm | Under investigation | ||
| Red Hat Enterprise Linux 9 | rust-bootupd | Under investigation | ||
| Red Hat OpenShift Container Platform 4 | rhcos | Under investigation |
Показывать по
Дополнительная информация
Статус:
EPSS
7 High
CVSS3
Связанные уязвимости
A command injection vulnerability was discovered in the `rpmuncompress` utility of RPM. When extracting certain archive formats (ZIP, 7z, GEM) to a specified destination directory, the tool inserts the archive's top-level folder name into a shell command without properly sanitizing it. A specially crafted archive containing shell metacharacters in its folder name can execute arbitrary commands as the user running the extraction.
A command injection vulnerability was discovered in the `rpmuncompress` utility of RPM. When extracting certain archive formats (ZIP, 7z, GEM) to a specified destination directory, the tool inserts the archive's top-level folder name into a shell command without properly sanitizing it. A specially crafted archive containing shell metacharacters in its folder name can execute arbitrary commands as the user running the extraction.
A command injection vulnerability was discovered in the `rpmuncompress ...
A command injection vulnerability was discovered in the `rpmuncompress` utility of RPM. When extracting certain archive formats (ZIP, 7z, GEM) to a specified destination directory, the tool inserts the archive's top-level folder name into a shell command without properly sanitizing it. A specially crafted archive containing shell metacharacters in its folder name can execute arbitrary commands as the user running the extraction.
EPSS
7 High
CVSS3