CVE-2012-0815

The headerVerifyInfo function in lib/header.c in RPM before 4.9.1.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a negative value in a region offset of a package header, which is not properly handled in a numeric range comparison.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 91%
Affected Products (NVD)
VendorProductVersion
rpmrpm
𝑥
≤ 4.9.1.2
rpmrpm
1.2
rpmrpm
1.3
rpmrpm
1.3.1
rpmrpm
1.4
rpmrpm
1.4.1
rpmrpm
1.4.2
rpmrpm
1.4.2\/a
rpmrpm
1.4.3
rpmrpm
1.4.4
rpmrpm
1.4.5
rpmrpm
1.4.6
rpmrpm
1.4.7
rpmrpm
2.0
rpmrpm
2.0.1
rpmrpm
2.0.2
rpmrpm
2.0.3
rpmrpm
2.0.4
rpmrpm
2.0.5
rpmrpm
2.0.6
rpmrpm
2.0.7
rpmrpm
2.0.8
rpmrpm
2.0.9
rpmrpm
2.0.10
rpmrpm
2.0.11
rpmrpm
2.1
rpmrpm
2.1.1
rpmrpm
2.1.2
rpmrpm
2.2
rpmrpm
2.2.1
rpmrpm
2.2.2
rpmrpm
2.2.3
rpmrpm
2.2.3.10
rpmrpm
2.2.3.11
rpmrpm
2.2.4
rpmrpm
2.2.5
rpmrpm
2.2.6
rpmrpm
2.2.7
rpmrpm
2.2.8
rpmrpm
2.2.9
rpmrpm
2.2.10
rpmrpm
2.2.11
rpmrpm
2.3
rpmrpm
2.3.1
rpmrpm
2.3.2
rpmrpm
2.3.3
rpmrpm
2.3.4
rpmrpm
2.3.5
rpmrpm
2.3.6
rpmrpm
2.3.7
rpmrpm
2.3.8
rpmrpm
2.3.9
rpmrpm
2.4.1
rpmrpm
2.4.2
rpmrpm
2.4.3
rpmrpm
2.4.4
rpmrpm
2.4.5
rpmrpm
2.4.6
rpmrpm
2.4.8
rpmrpm
2.4.9
rpmrpm
2.4.11
rpmrpm
2.4.12
rpmrpm
2.5
rpmrpm
2.5.1
rpmrpm
2.5.2
rpmrpm
2.5.3
rpmrpm
2.5.4
rpmrpm
2.5.5
rpmrpm
2.5.6
rpmrpm
2.6.7
rpmrpm
3.0
rpmrpm
3.0.1
rpmrpm
3.0.2
rpmrpm
3.0.3
rpmrpm
3.0.4
rpmrpm
3.0.5
rpmrpm
3.0.6
rpmrpm
4.0.
rpmrpm
4.0.1
rpmrpm
4.0.2
rpmrpm
4.0.3
rpmrpm
4.0.4
rpmrpm
4.1
rpmrpm
4.3.3
rpmrpm
4.4.2.1
rpmrpm
4.4.2.2
rpmrpm
4.4.2.3
rpmrpm
4.5.90
rpmrpm
4.6.0
rpmrpm
4.6.0:rc1
rpmrpm
4.6.0:rc2
rpmrpm
4.6.0:rc3
rpmrpm
4.6.0:rc4
rpmrpm
4.6.1
rpmrpm
4.7.0
rpmrpm
4.7.1
rpmrpm
4.7.2
rpmrpm
4.8.0
rpmrpm
4.8.1
rpmrpm
4.9.0
rpmrpm
4.9.0:alpha
rpmrpm
4.9.0:beta1
rpmrpm
4.9.0:rc1
rpmrpm
4.9.1
rpmrpm
4.9.1.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
rpm
bookworm
4.18.0+dfsg-1+deb12u1
fixed
bullseye
4.16.1.2+dfsg1-3
fixed
sid
4.20.0+dfsg-3
fixed
squeeze
no-dsa
trixie
4.20.0+dfsg-3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
rpm
hardy
ignored
lucid
Fixed 4.7.2-1lubuntu0.1
released
maverick
ignored
natty
ignored
oneiric
Fixed 4.9.0-7ubuntu0.1
released
precise
Fixed 4.9.1.1-1ubuntu0.1
released
quantal
not-affected
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
rpm
RHEL 6
0:4.8.0-19.el6_2.1
fixed
rpm-apidocs
RHEL 6
0:4.8.0-19.el6_2.1
fixed
rpm-build
RHEL 6
0:4.8.0-19.el6_2.1
fixed
rpm-cron
RHEL 6
0:4.8.0-19.el6_2.1
fixed
rpm-devel
RHEL 6
0:4.8.0-19.el6_2.1
fixed
rpm-libs
RHEL 6
0:4.8.0-19.el6_2.1
fixed
rpm-python
RHEL 6
0:4.8.0-19.el6_2.1
fixed
Common Weakness Enumeration
References