Executive Summary

Informations
NameCVE-2012-0061First vendor Publication2012-06-04
VendorCveLast vendor Modification2013-05-03

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:M/Au:N/C:P/I:P/A:P)
Cvss Base Score6.8Attack RangeNetwork
Cvss Impact Score6.4Attack ComplexityMedium
Cvss Expoit Score8.6AuthentificationNone Required
Calculate full CVSS 2.0 Vectors scores

Detail

The headerLoad function in lib/header.c in RPM before 4.9.1.3 does not properly validate region tags, which allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large region size in a package header.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0061

CWE : Common Weakness Enumeration

idName
CWE-20Improper Input Validation

CPE : Common Platform Enumeration

TypeDescriptionCount
Application105

Internal Sources (Detail)

SourceUrl
BIDhttp://www.securityfocus.com/bid/52865
CONFIRMhttp://rpm.org/gitweb?p=rpm.git;a=commitdiff;h=472e569562d4c90d7a298080e00528...
http://rpm.org/gitweb?p=rpm.git;a=commitdiff;h=858a328cd0f7d4bcd8500c78faaf00...
http://rpm.org/wiki/Releases/4.9.1.3
FEDORAhttp://lists.fedoraproject.org/pipermail/package-announce/2012-April/077960.html
http://lists.fedoraproject.org/pipermail/package-announce/2012-April/078819.html
http://lists.fedoraproject.org/pipermail/package-announce/2012-April/078907.html
MISChttps://bugzilla.redhat.com/show_bug.cgi?id=798585
OSVDBhttp://www.osvdb.org/81010
REDHAThttp://rhn.redhat.com/errata/RHSA-2012-0451.html
http://rhn.redhat.com/errata/RHSA-2012-0531.html
SECTRACKhttp://www.securitytracker.com/id?1026882
SECUNIAhttp://secunia.com/advisories/48651
http://secunia.com/advisories/48716
http://secunia.com/advisories/49110
SUSEhttps://hermes.opensuse.org/messages/14440932
https://hermes.opensuse.org/messages/14441362
UBUNTUhttp://www.ubuntu.com/usn/USN-1695-1
XFhttp://xforce.iss.net/xforce/xfdb/74583

Alert History

If you want to see full details history, please login or register.
0
1
2
3
DateInformations
2013-05-10 22:31:05
  • Multiple Updates
2013-05-04 17:19:44
  • Multiple Updates
2013-02-07 13:19:58
  • Multiple Updates
2012-12-06 13:20:02
  • Multiple Updates