CVE Vulnerabilities

CVE-2012-0815

Published: Jun 04, 2012 | Modified: Nov 07, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
7.6 IMPORTANT
AV:N/AC:H/Au:N/C:C/I:C/A:C
RedHat/V3
Ubuntu
LOW

The headerVerifyInfo function in lib/header.c in RPM before 4.9.1.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a negative value in a region offset of a package header, which is not properly handled in a numeric range comparison.

Affected Software

Name Vendor Start Version End Version
Rpm Rpm * 4.9.1.2 (including)
Rpm Rpm 1.2 (including) 1.2 (including)
Rpm Rpm 1.3 (including) 1.3 (including)
Rpm Rpm 1.3.1 (including) 1.3.1 (including)
Rpm Rpm 1.4 (including) 1.4 (including)
Rpm Rpm 1.4.1 (including) 1.4.1 (including)
Rpm Rpm 1.4.2 (including) 1.4.2 (including)
Rpm Rpm 1.4.2/a (including) 1.4.2/a (including)
Rpm Rpm 1.4.3 (including) 1.4.3 (including)
Rpm Rpm 1.4.4 (including) 1.4.4 (including)
Rpm Rpm 1.4.5 (including) 1.4.5 (including)
Rpm Rpm 1.4.6 (including) 1.4.6 (including)
Rpm Rpm 1.4.7 (including) 1.4.7 (including)
Rpm Rpm 2.0 (including) 2.0 (including)
Rpm Rpm 2.0.1 (including) 2.0.1 (including)
Rpm Rpm 2.0.2 (including) 2.0.2 (including)
Rpm Rpm 2.0.3 (including) 2.0.3 (including)
Rpm Rpm 2.0.4 (including) 2.0.4 (including)
Rpm Rpm 2.0.5 (including) 2.0.5 (including)
Rpm Rpm 2.0.6 (including) 2.0.6 (including)
Rpm Rpm 2.0.7 (including) 2.0.7 (including)
Rpm Rpm 2.0.8 (including) 2.0.8 (including)
Rpm Rpm 2.0.9 (including) 2.0.9 (including)
Rpm Rpm 2.0.10 (including) 2.0.10 (including)
Rpm Rpm 2.0.11 (including) 2.0.11 (including)
Rpm Rpm 2.1 (including) 2.1 (including)
Rpm Rpm 2.1.1 (including) 2.1.1 (including)
Rpm Rpm 2.1.2 (including) 2.1.2 (including)
Rpm Rpm 2.2 (including) 2.2 (including)
Rpm Rpm 2.2.1 (including) 2.2.1 (including)
Rpm Rpm 2.2.2 (including) 2.2.2 (including)
Rpm Rpm 2.2.3 (including) 2.2.3 (including)
Rpm Rpm 2.2.3.10 (including) 2.2.3.10 (including)
Rpm Rpm 2.2.3.11 (including) 2.2.3.11 (including)
Rpm Rpm 2.2.4 (including) 2.2.4 (including)
Rpm Rpm 2.2.5 (including) 2.2.5 (including)
Rpm Rpm 2.2.6 (including) 2.2.6 (including)
Rpm Rpm 2.2.7 (including) 2.2.7 (including)
Rpm Rpm 2.2.8 (including) 2.2.8 (including)
Rpm Rpm 2.2.9 (including) 2.2.9 (including)
Rpm Rpm 2.2.10 (including) 2.2.10 (including)
Rpm Rpm 2.2.11 (including) 2.2.11 (including)
Rpm Rpm 2.3 (including) 2.3 (including)
Rpm Rpm 2.3.1 (including) 2.3.1 (including)
Rpm Rpm 2.3.2 (including) 2.3.2 (including)
Rpm Rpm 2.3.3 (including) 2.3.3 (including)
Rpm Rpm 2.3.4 (including) 2.3.4 (including)
Rpm Rpm 2.3.5 (including) 2.3.5 (including)
Rpm Rpm 2.3.6 (including) 2.3.6 (including)
Rpm Rpm 2.3.7 (including) 2.3.7 (including)
Rpm Rpm 2.3.8 (including) 2.3.8 (including)
Rpm Rpm 2.3.9 (including) 2.3.9 (including)
Rpm Rpm 2.4.1 (including) 2.4.1 (including)
Rpm Rpm 2.4.2 (including) 2.4.2 (including)
Rpm Rpm 2.4.3 (including) 2.4.3 (including)
Rpm Rpm 2.4.4 (including) 2.4.4 (including)
Rpm Rpm 2.4.5 (including) 2.4.5 (including)
Rpm Rpm 2.4.6 (including) 2.4.6 (including)
Rpm Rpm 2.4.8 (including) 2.4.8 (including)
Rpm Rpm 2.4.9 (including) 2.4.9 (including)
Rpm Rpm 2.4.11 (including) 2.4.11 (including)
Rpm Rpm 2.4.12 (including) 2.4.12 (including)
Rpm Rpm 2.5 (including) 2.5 (including)
Rpm Rpm 2.5.1 (including) 2.5.1 (including)
Rpm Rpm 2.5.2 (including) 2.5.2 (including)
Rpm Rpm 2.5.3 (including) 2.5.3 (including)
Rpm Rpm 2.5.4 (including) 2.5.4 (including)
Rpm Rpm 2.5.5 (including) 2.5.5 (including)
Rpm Rpm 2.5.6 (including) 2.5.6 (including)
Rpm Rpm 2.6.7 (including) 2.6.7 (including)
Rpm Rpm 3.0 (including) 3.0 (including)
Rpm Rpm 3.0.1 (including) 3.0.1 (including)
Rpm Rpm 3.0.2 (including) 3.0.2 (including)
Rpm Rpm 3.0.3 (including) 3.0.3 (including)
Rpm Rpm 3.0.4 (including) 3.0.4 (including)
Rpm Rpm 3.0.5 (including) 3.0.5 (including)
Rpm Rpm 3.0.6 (including) 3.0.6 (including)
Rpm Rpm 4.0. (including) 4.0. (including)
Rpm Rpm 4.0.1 (including) 4.0.1 (including)
Rpm Rpm 4.0.2 (including) 4.0.2 (including)
Rpm Rpm 4.0.3 (including) 4.0.3 (including)
Rpm Rpm 4.0.4 (including) 4.0.4 (including)
Rpm Rpm 4.1 (including) 4.1 (including)
Rpm Rpm 4.3.3 (including) 4.3.3 (including)
Rpm Rpm 4.4.2.1 (including) 4.4.2.1 (including)
Rpm Rpm 4.4.2.2 (including) 4.4.2.2 (including)
Rpm Rpm 4.4.2.3 (including) 4.4.2.3 (including)
Rpm Rpm 4.5.90 (including) 4.5.90 (including)
Rpm Rpm 4.6.0 (including) 4.6.0 (including)
Rpm Rpm 4.6.0-rc1 (including) 4.6.0-rc1 (including)
Rpm Rpm 4.6.0-rc2 (including) 4.6.0-rc2 (including)
Rpm Rpm 4.6.0-rc3 (including) 4.6.0-rc3 (including)
Rpm Rpm 4.6.0-rc4 (including) 4.6.0-rc4 (including)
Rpm Rpm 4.6.1 (including) 4.6.1 (including)
Rpm Rpm 4.7.0 (including) 4.7.0 (including)
Rpm Rpm 4.7.1 (including) 4.7.1 (including)
Rpm Rpm 4.7.2 (including) 4.7.2 (including)
Rpm Rpm 4.8.0 (including) 4.8.0 (including)
Rpm Rpm 4.8.1 (including) 4.8.1 (including)
Rpm Rpm 4.9.0 (including) 4.9.0 (including)
Rpm Rpm 4.9.0-alpha (including) 4.9.0-alpha (including)
Rpm Rpm 4.9.0-beta1 (including) 4.9.0-beta1 (including)
Rpm Rpm 4.9.0-rc1 (including) 4.9.0-rc1 (including)
Rpm Rpm 4.9.1 (including) 4.9.1 (including)
Rpm Rpm 4.9.1.1 (including) 4.9.1.1 (including)
Red Hat Enterprise Linux 3 Extended Lifecycle Support RedHat rpm-0:4.2.3-36_nonptl *
Red Hat Enterprise Linux 4 Extended Lifecycle Support RedHat rpm-0:4.3.3-36_nonptl.el4 *
Red Hat Enterprise Linux 5 RedHat rpm-0:4.4.2.3-28.el5_8 *
Red Hat Enterprise Linux 5.3 Long Life RedHat rpm-0:4.4.2.3-9.el5_3.3 *
Red Hat Enterprise Linux 5.6 EUS - Server Only RedHat rpm-0:4.4.2.3-22.el5_6.3 *
Red Hat Enterprise Linux 6 RedHat rpm-0:4.8.0-19.el6_2.1 *
Red Hat Enterprise Linux 6.0 EUS - Server Only RedHat rpm-0:4.8.0-12.el6_0.2 *
Red Hat Enterprise Linux 6.1 EUS - Server Only RedHat rpm-0:4.8.0-16.el6_1.2 *
Rpm Ubuntu hardy *
Rpm Ubuntu lucid *
Rpm Ubuntu maverick *
Rpm Ubuntu natty *
Rpm Ubuntu oneiric *
Rpm Ubuntu precise *
Rpm Ubuntu upstream *

References