CVE Vulnerabilities

CVE-2013-6435

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Published: Dec 16, 2014 | Modified: Feb 13, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.6 HIGH
AV:N/AC:H/Au:N/C:C/I:C/A:C
RedHat/V2
7.6 IMPORTANT
AV:N/AC:H/Au:N/C:C/I:C/A:C
RedHat/V3
Ubuntu
MEDIUM

Race condition in RPM 4.11.1 and earlier allows remote attackers to execute arbitrary code via a crafted RPM file whose installation extracts the contents to temporary files before validating the signature, as demonstrated by installing a file in the /etc/cron.d directory.

Weakness

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

Affected Software

Name Vendor Start Version End Version
Rpm Rpm * 4.11.1 (including)
Rpm Rpm 1.2 (including) 1.2 (including)
Rpm Rpm 1.3 (including) 1.3 (including)
Rpm Rpm 1.3.1 (including) 1.3.1 (including)
Rpm Rpm 1.4 (including) 1.4 (including)
Rpm Rpm 1.4.1 (including) 1.4.1 (including)
Rpm Rpm 1.4.2 (including) 1.4.2 (including)
Rpm Rpm 1.4.2/a (including) 1.4.2/a (including)
Rpm Rpm 1.4.3 (including) 1.4.3 (including)
Rpm Rpm 1.4.4 (including) 1.4.4 (including)
Rpm Rpm 1.4.5 (including) 1.4.5 (including)
Rpm Rpm 1.4.6 (including) 1.4.6 (including)
Rpm Rpm 1.4.7 (including) 1.4.7 (including)
Rpm Rpm 2.0 (including) 2.0 (including)
Rpm Rpm 2.0.1 (including) 2.0.1 (including)
Rpm Rpm 2.0.2 (including) 2.0.2 (including)
Rpm Rpm 2.0.3 (including) 2.0.3 (including)
Rpm Rpm 2.0.4 (including) 2.0.4 (including)
Rpm Rpm 2.0.5 (including) 2.0.5 (including)
Rpm Rpm 2.0.6 (including) 2.0.6 (including)
Rpm Rpm 2.0.7 (including) 2.0.7 (including)
Rpm Rpm 2.0.8 (including) 2.0.8 (including)
Rpm Rpm 2.0.9 (including) 2.0.9 (including)
Rpm Rpm 2.0.10 (including) 2.0.10 (including)
Rpm Rpm 2.0.11 (including) 2.0.11 (including)
Rpm Rpm 2.1 (including) 2.1 (including)
Rpm Rpm 2.1.1 (including) 2.1.1 (including)
Rpm Rpm 2.1.2 (including) 2.1.2 (including)
Rpm Rpm 2.2 (including) 2.2 (including)
Rpm Rpm 2.2.1 (including) 2.2.1 (including)
Rpm Rpm 2.2.2 (including) 2.2.2 (including)
Rpm Rpm 2.2.3 (including) 2.2.3 (including)
Rpm Rpm 2.2.3.10 (including) 2.2.3.10 (including)
Rpm Rpm 2.2.3.11 (including) 2.2.3.11 (including)
Rpm Rpm 2.2.4 (including) 2.2.4 (including)
Rpm Rpm 2.2.5 (including) 2.2.5 (including)
Rpm Rpm 2.2.6 (including) 2.2.6 (including)
Rpm Rpm 2.2.7 (including) 2.2.7 (including)
Rpm Rpm 2.2.8 (including) 2.2.8 (including)
Rpm Rpm 2.2.9 (including) 2.2.9 (including)
Rpm Rpm 2.2.10 (including) 2.2.10 (including)
Rpm Rpm 2.2.11 (including) 2.2.11 (including)
Rpm Rpm 2.3 (including) 2.3 (including)
Rpm Rpm 2.3.1 (including) 2.3.1 (including)
Rpm Rpm 2.3.2 (including) 2.3.2 (including)
Rpm Rpm 2.3.3 (including) 2.3.3 (including)
Rpm Rpm 2.3.4 (including) 2.3.4 (including)
Rpm Rpm 2.3.5 (including) 2.3.5 (including)
Rpm Rpm 2.3.6 (including) 2.3.6 (including)
Rpm Rpm 2.3.7 (including) 2.3.7 (including)
Rpm Rpm 2.3.8 (including) 2.3.8 (including)
Rpm Rpm 2.3.9 (including) 2.3.9 (including)
Rpm Rpm 2.4.1 (including) 2.4.1 (including)
Rpm Rpm 2.4.2 (including) 2.4.2 (including)
Rpm Rpm 2.4.3 (including) 2.4.3 (including)
Rpm Rpm 2.4.4 (including) 2.4.4 (including)
Rpm Rpm 2.4.5 (including) 2.4.5 (including)
Rpm Rpm 2.4.6 (including) 2.4.6 (including)
Rpm Rpm 2.4.8 (including) 2.4.8 (including)
Rpm Rpm 2.4.9 (including) 2.4.9 (including)
Rpm Rpm 2.4.11 (including) 2.4.11 (including)
Rpm Rpm 2.4.12 (including) 2.4.12 (including)
Rpm Rpm 2.5 (including) 2.5 (including)
Rpm Rpm 2.5.1 (including) 2.5.1 (including)
Rpm Rpm 2.5.2 (including) 2.5.2 (including)
Rpm Rpm 2.5.3 (including) 2.5.3 (including)
Rpm Rpm 2.5.4 (including) 2.5.4 (including)
Rpm Rpm 2.5.5 (including) 2.5.5 (including)
Rpm Rpm 2.5.6 (including) 2.5.6 (including)
Rpm Rpm 2.6.7 (including) 2.6.7 (including)
Rpm Rpm 3.0 (including) 3.0 (including)
Rpm Rpm 3.0.1 (including) 3.0.1 (including)
Rpm Rpm 3.0.2 (including) 3.0.2 (including)
Rpm Rpm 3.0.3 (including) 3.0.3 (including)
Rpm Rpm 3.0.4 (including) 3.0.4 (including)
Rpm Rpm 3.0.5 (including) 3.0.5 (including)
Rpm Rpm 3.0.6 (including) 3.0.6 (including)
Rpm Rpm 4.0. (including) 4.0. (including)
Rpm Rpm 4.0.1 (including) 4.0.1 (including)
Rpm Rpm 4.0.2 (including) 4.0.2 (including)
Rpm Rpm 4.0.3 (including) 4.0.3 (including)
Rpm Rpm 4.0.4 (including) 4.0.4 (including)
Rpm Rpm 4.1 (including) 4.1 (including)
Rpm Rpm 4.3.3 (including) 4.3.3 (including)
Rpm Rpm 4.4.2.1 (including) 4.4.2.1 (including)
Rpm Rpm 4.4.2.2 (including) 4.4.2.2 (including)
Rpm Rpm 4.4.2.3 (including) 4.4.2.3 (including)
Rpm Rpm 4.5.90 (including) 4.5.90 (including)
Rpm Rpm 4.6.0 (including) 4.6.0 (including)
Rpm Rpm 4.6.0-rc1 (including) 4.6.0-rc1 (including)
Rpm Rpm 4.6.0-rc2 (including) 4.6.0-rc2 (including)
Rpm Rpm 4.6.0-rc3 (including) 4.6.0-rc3 (including)
Rpm Rpm 4.6.0-rc4 (including) 4.6.0-rc4 (including)
Rpm Rpm 4.6.1 (including) 4.6.1 (including)
Rpm Rpm 4.7.0 (including) 4.7.0 (including)
Rpm Rpm 4.7.1 (including) 4.7.1 (including)
Rpm Rpm 4.7.2 (including) 4.7.2 (including)
Rpm Rpm 4.8.0 (including) 4.8.0 (including)
Rpm Rpm 4.8.1 (including) 4.8.1 (including)
Rpm Rpm 4.9.0 (including) 4.9.0 (including)
Rpm Rpm 4.9.0-alpha (including) 4.9.0-alpha (including)
Rpm Rpm 4.9.0-beta1 (including) 4.9.0-beta1 (including)
Rpm Rpm 4.9.0-rc1 (including) 4.9.0-rc1 (including)
Rpm Rpm 4.9.1 (including) 4.9.1 (including)
Rpm Rpm 4.9.1.1 (including) 4.9.1.1 (including)
Rpm Rpm 4.9.1.2 (including) 4.9.1.2 (including)
Rpm Rpm 4.10.0 (including) 4.10.0 (including)
Rpm Rpm 4.10.1 (including) 4.10.1 (including)
Rpm Rpm 4.10.2 (including) 4.10.2 (including)
Red Hat Enterprise Linux 5 RedHat rpm-0:4.4.2.3-36.el5_11 *
Red Hat Enterprise Linux 5.6 Long Life RedHat rpm-0:4.4.2.3-24.el5_6 *
Red Hat Enterprise Linux 5.9 Extended Update Support RedHat rpm-0:4.4.2.3-34.el5_9 *
Red Hat Enterprise Linux 6 RedHat rpm-0:4.8.0-38.el6_6 *
Red Hat Enterprise Linux 6.2 Advanced Update Support RedHat rpm-0:4.8.0-20.el6_2.1 *
Red Hat Enterprise Linux 6.4 Extended Update Support RedHat rpm-0:4.8.0-33.el6_4 *
Red Hat Enterprise Linux 6.5 Extended Update Support RedHat rpm-0:4.8.0-38.el6_5 *
Red Hat Enterprise Linux 7 RedHat rpm-0:4.11.1-18.el7_0 *
Rpm Ubuntu lucid *
Rpm Ubuntu precise *
Rpm Ubuntu trusty *
Rpm Ubuntu upstream *
Rpm Ubuntu utopic *

Potential Mitigations

References