RPM 4.4.x through 4.9.x, probably before 4.9.1.2, allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via an rpm package with crafted headers and offsets that are not properly handled when a package is queried or installed, related to (1) the regionSwab function, (2) the headerLoad function, and (3) multiple functions in rpmio/rpmpgp.c.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade poptUpgrade rpmUpgrade rpm-pythonUpgrade rpm-develUpgrade rpm-libsUpgrade rpm-buildUpgrade rpm-apidocs | Dec 1, 2016 | Dec 24, 2011 |
| Debian | — | Upgrade rpm | Jul 30, 2024 | Dec 24, 2011 |
| Gentoo Linux | — | Upgrade app-arch/rpm. | Oct 30, 2017 | Dec 24, 2011 |
| Oracle_linux | — | Upgrade rpm-libsUpgrade rpm-cronUpgrade poptUpgrade rpm-pythonUpgrade rpm-develUpgrade rpmUpgrade rpm-buildUpgrade rpm-apidocs | Oct 16, 2024 | Dec 24, 2011 |
| Suse | — | Upgrade popt-devel-64bitUpgrade rpm-pythonUpgrade popt-32bitUpgrade poptUpgrade rpm-develUpgrade popt-develUpgrade popt-x86Upgrade sap-aio-releaseUpgrade rpm-32bitUpgrade rpmUpgrade popt-64bitUpgrade popt-devel-32bit | Feb 17, 2015 | Dec 24, 2011 |
| Ubuntu | — | Upgrade rpm | Nov 8, 2024 | Dec 24, 2011 |
| Vmsa 2012 0001 | — | Upgrade VMware ESX 4.0 to build number 660575Upgrade VMware ESX 4.1 to build number 582267 | Feb 3, 2012 | Dec 24, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub