CVE-2012-0815

EUVD-2012-0842
The headerVerifyInfo function in lib/header.c in RPM before 4.9.1.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a negative value in a region offset of a package header, which is not properly handled in a numeric range comparison.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 91%
Affected Products (NVD)
VendorProductVersion
rpmrpm
𝑥
≤ 4.9.1.2
rpmrpm
1.2
rpmrpm
1.3
rpmrpm
1.3.1
rpmrpm
1.4
rpmrpm
1.4.1
rpmrpm
1.4.2
rpmrpm
1.4.2\/a
rpmrpm
1.4.3
rpmrpm
1.4.4
rpmrpm
1.4.5
rpmrpm
1.4.6
rpmrpm
1.4.7
rpmrpm
2.0
rpmrpm
2.0.1
rpmrpm
2.0.2
rpmrpm
2.0.3
rpmrpm
2.0.4
rpmrpm
2.0.5
rpmrpm
2.0.6
rpmrpm
2.0.7
rpmrpm
2.0.8
rpmrpm
2.0.9
rpmrpm
2.0.10
rpmrpm
2.0.11
rpmrpm
2.1
rpmrpm
2.1.1
rpmrpm
2.1.2
rpmrpm
2.2
rpmrpm
2.2.1
rpmrpm
2.2.2
rpmrpm
2.2.3
rpmrpm
2.2.3.10
rpmrpm
2.2.3.11
rpmrpm
2.2.4
rpmrpm
2.2.5
rpmrpm
2.2.6
rpmrpm
2.2.7
rpmrpm
2.2.8
rpmrpm
2.2.9
rpmrpm
2.2.10
rpmrpm
2.2.11
rpmrpm
2.3
rpmrpm
2.3.1
rpmrpm
2.3.2
rpmrpm
2.3.3
rpmrpm
2.3.4
rpmrpm
2.3.5
rpmrpm
2.3.6
rpmrpm
2.3.7
rpmrpm
2.3.8
rpmrpm
2.3.9
rpmrpm
2.4.1
rpmrpm
2.4.2
rpmrpm
2.4.3
rpmrpm
2.4.4
rpmrpm
2.4.5
rpmrpm
2.4.6
rpmrpm
2.4.8
rpmrpm
2.4.9
rpmrpm
2.4.11
rpmrpm
2.4.12
rpmrpm
2.5
rpmrpm
2.5.1
rpmrpm
2.5.2
rpmrpm
2.5.3
rpmrpm
2.5.4
rpmrpm
2.5.5
rpmrpm
2.5.6
rpmrpm
2.6.7
rpmrpm
3.0
rpmrpm
3.0.1
rpmrpm
3.0.2
rpmrpm
3.0.3
rpmrpm
3.0.4
rpmrpm
3.0.5
rpmrpm
3.0.6
rpmrpm
4.0.
rpmrpm
4.0.1
rpmrpm
4.0.2
rpmrpm
4.0.3
rpmrpm
4.0.4
rpmrpm
4.1
rpmrpm
4.3.3
rpmrpm
4.4.2.1
rpmrpm
4.4.2.2
rpmrpm
4.4.2.3
rpmrpm
4.5.90
rpmrpm
4.6.0
rpmrpm
4.6.0:rc1
rpmrpm
4.6.0:rc2
rpmrpm
4.6.0:rc3
rpmrpm
4.6.0:rc4
rpmrpm
4.6.1
rpmrpm
4.7.0
rpmrpm
4.7.1
rpmrpm
4.7.2
rpmrpm
4.8.0
rpmrpm
4.8.1
rpmrpm
4.9.0
rpmrpm
4.9.0:alpha
rpmrpm
4.9.0:beta1
rpmrpm
4.9.0:rc1
rpmrpm
4.9.1
rpmrpm
4.9.1.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
rpm
bookworm
4.18.0+dfsg-1+deb12u1
fixed
bullseye
4.16.1.2+dfsg1-3
fixed
sid
4.20.0+dfsg-3
fixed
squeeze
no-dsa
trixie
4.20.0+dfsg-3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
rpm
hardy
ignored
lucid
Fixed 4.7.2-1lubuntu0.1
released
maverick
ignored
natty
ignored
oneiric
Fixed 4.9.0-7ubuntu0.1
released
precise
Fixed 4.9.1.1-1ubuntu0.1
released
quantal
not-affected
Common Weakness Enumeration
References