Heap-based buffer overflow in the showQueryPackage function in librpm in RPM Package Manager 4.4.8, when the LANG environment variable is set to ru_RU.UTF-8, might allow user-assisted attackers to execute arbitrary code via crafted RPM packages.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Package_manager | Rpm | 4.4.8 (including) | 4.4.8 (including) |
Rpm | Ubuntu | dapper | * |
Rpm | Ubuntu | devel | * |
Rpm | Ubuntu | edgy | * |
Rpm | Ubuntu | feisty | * |