Количество 6
Количество 6
CVE-2026-84233
(A flaw was found in rpm. A local attacker could supply a specially cra ...)
CVE-2026-84233
A flaw was found in rpm. A local attacker could supply a specially crafted `.gem` filename containing RPM macro syntax. When a user or automated workflow invokes `rpmuncompress -x` on this file, the macro expansion occurs during command construction. This allows the attacker to execute arbitrary commands with the privileges of the invoking account, leading to a compromise of confidentiality, integrity, and availability.
CVE-2026-84233
A flaw was found in rpm. A local attacker could supply a specially crafted `.gem` filename containing RPM macro syntax. When a user or automated workflow invokes `rpmuncompress -x` on this file, the macro expansion occurs during command construction. This allows the attacker to execute arbitrary commands with the privileges of the invoking account, leading to a compromise of confidentiality, integrity, and availability.
CVE-2026-84233
Rpm: command execution via macro expansion in `rpmuncompress -x` for crafted `.gem` filenames
CVE-2026-84233
A flaw was found in rpm. A local attacker could supply a specially cra ...
GHSA-j9c4-6ppm-mvh4
A flaw was found in rpm. A local attacker could supply a specially crafted `.gem` filename containing RPM macro syntax. When a user or automated workflow invokes `rpmuncompress -x` on this file, the macro expansion occurs during command construction. This allows the attacker to execute arbitrary commands with the privileges of the invoking account, leading to a compromise of confidentiality, integrity, and availability.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-84233 (A flaw was found in rpm. A local attacker could supply a specially cra ...) | CVSS3: 7 | 0% Низкий | 15 дней назад | |
CVE-2026-84233 A flaw was found in rpm. A local attacker could supply a specially crafted `.gem` filename containing RPM macro syntax. When a user or automated workflow invokes `rpmuncompress -x` on this file, the macro expansion occurs during command construction. This allows the attacker to execute arbitrary commands with the privileges of the invoking account, leading to a compromise of confidentiality, integrity, and availability. | CVSS3: 7 | 0% Низкий | 15 дней назад | |
CVE-2026-84233 A flaw was found in rpm. A local attacker could supply a specially crafted `.gem` filename containing RPM macro syntax. When a user or automated workflow invokes `rpmuncompress -x` on this file, the macro expansion occurs during command construction. This allows the attacker to execute arbitrary commands with the privileges of the invoking account, leading to a compromise of confidentiality, integrity, and availability. | CVSS3: 7 | 0% Низкий | 15 дней назад | |
CVE-2026-84233 Rpm: command execution via macro expansion in `rpmuncompress -x` for crafted `.gem` filenames | 0% Низкий | 10 дней назад | ||
CVE-2026-84233 A flaw was found in rpm. A local attacker could supply a specially cra ... | CVSS3: 7 | 0% Низкий | 15 дней назад | |
GHSA-j9c4-6ppm-mvh4 A flaw was found in rpm. A local attacker could supply a specially crafted `.gem` filename containing RPM macro syntax. When a user or automated workflow invokes `rpmuncompress -x` on this file, the macro expansion occurs during command construction. This allows the attacker to execute arbitrary commands with the privileges of the invoking account, leading to a compromise of confidentiality, integrity, and availability. | CVSS3: 7 | 0% Низкий | 15 дней назад |
Уязвимостей на страницу