RPM 4.4.x through 4.9.x, probably before 4.9.1.2, allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via an rpm package with crafted headers and offsets that are not properly handled when a package is queried or installed, related to (1) the regionSwab function, (2) the headerLoad function, and (3) multiple functions in rpmio/rpmpgp.c.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade rpm-libsUpgrade rpm-apidocsUpgrade rpm-buildUpgrade rpm-develUpgrade rpm-pythonUpgrade rpmUpgrade popt | Dec 1, 2016 | Dec 24, 2011 |
| Debian | — | Upgrade rpm | Jul 30, 2024 | Dec 24, 2011 |
| Gentoo Linux | — | Upgrade app-arch/rpm. | Oct 30, 2017 | Dec 24, 2011 |
| Oracle_linux | — | Upgrade rpm-develUpgrade rpmUpgrade rpm-apidocsUpgrade rpm-buildUpgrade rpm-pythonUpgrade rpm-cronUpgrade rpm-libsUpgrade popt | Oct 16, 2024 | Dec 24, 2011 |
| Suse | — | Upgrade rpm-develUpgrade popt-devel-64bitUpgrade poptUpgrade popt-32bitUpgrade rpm-pythonUpgrade popt-x86Upgrade popt-develUpgrade rpm-32bitUpgrade rpmUpgrade popt-64bitUpgrade sap-aio-releaseUpgrade popt-devel-32bit | Feb 17, 2015 | Dec 24, 2011 |
| Ubuntu | — | Upgrade rpm | Nov 8, 2024 | Dec 24, 2011 |
| Vmsa 2012 0001 | — | Upgrade VMware ESX 4.0 to build number 660575Upgrade VMware ESX 4.1 to build number 582267 | Feb 3, 2012 | Dec 24, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub