Skip to main content

Vendor archive

rpm CVEs

Beta · best-effort

26 CVEs tagged to vendor rpm2 Critical, 12 High, 12 Medium, 0 Low, 0 Unrated.

CVE-2024-1929

Published May 8, 2024

Local Root Exploit via Configuration Dictionary in dnf5daemon-server before 5.1.17 allows a malicious user to impact Confidentiality and Integrity via Configuration Dictionary.…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-35939

Published Aug 26, 2022

It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to be created. A local unprivileg…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-3521

Published Aug 22, 2022

There is a flaw in RPM's signature functionality. OpenPGP subkeys are associated with a primary key via a "binding signature." RPM does not check the binding signature of subkeys…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-20266

Published Apr 30, 2021

A flaw was found in RPM's hdrblobInit() in lib/header.c. This flaw allows an attacker who can modify the rpmdb to cause an out-of-bounds read. The highest threat from this vulnera…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-3817

Published Mar 27, 2019

A use-after-free flaw has been discovered in libcomps before version 0.1.10 in the way ObjMRTrees are merged. An attacker, who is able to make an application read a crafted comps…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-7500

Published Aug 13, 2018

It was found that rpm did not properly handle RPM installations when a destination path was a symbolic link to a directory, possibly changing ownership and permissions of an arbit…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2017-7501

Published Nov 22, 2017

It was found that versions of rpm before 4.13.0.2 use temporary files with predictable names when installing an RPM. An attacker with ability to write in a directory where files w…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2014-8118

Published Dec 16, 2014

Integer overflow in RPM 4.12 and earlier allows remote attackers to execute arbitrary code via a crafted CPIO header in the payload section of an RPM file, which triggers a stack-…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2013-6435

Published Dec 16, 2014

Race condition in RPM 4.11.1 and earlier allows remote attackers to execute arbitrary code via a crafted RPM file whose installation extracts the contents to temporary files befor…

CVSS 7.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2012-6088

Published Jan 18, 2013

The rpmpkgRead function in lib/package.c in RPM 4.10.x before 4.10.2 does not return an error code in certain situations involving an "unparseable signature," which allows remote…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0815

Published Jun 4, 2012

The headerVerifyInfo function in lib/header.c in RPM before 4.9.1.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a negative…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0061

Published Jun 4, 2012

The headerLoad function in lib/header.c in RPM before 4.9.1.3 does not properly validate region tags, which allows user-assisted remote attackers to cause a denial of service (cra…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0060

Published Jun 4, 2012

RPM before 4.9.1.3 does not properly validate region tags, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an invalid re…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3378

Published Dec 24, 2011

RPM 4.4.x through 4.9.x, probably before 4.9.1.2, allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via an rpm package w…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-2199

Published Jun 8, 2010

lib/fsm.c in RPM 4.8.0 and earlier does not properly reset the metadata of an executable file during replacement of the file in an RPM package upgrade or deletion of the file in a…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2010-2198

Published Jun 8, 2010

lib/fsm.c in RPM 4.8.0 and earlier does not properly reset the metadata of an executable file during replacement of the file in an RPM package upgrade or deletion of the file in a…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2010-2197

Published Jun 8, 2010

rpmbuild in RPM 4.8.0 and earlier does not properly parse the syntax of spec files, which allows user-assisted remote attackers to remove home directories via vectors involving a…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-2059

Published Jun 8, 2010

lib/fsm.c in RPM 4.8.0 and unspecified 4.7.x and 4.6.x versions, and RPM before 4.4.3, does not properly reset the metadata of an executable file during replacement of the file in…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4889

Published Jun 8, 2010

lib/fsm.c in RPM before 4.4.3 does not properly reset the metadata of an executable file during deletion of the file in an RPM package removal, which might allow local users to ga…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 26 CVEsPage 1 of 2