CVE-2006-5466
published 2006-11-06CVE-2006-5466: Heap-based buffer overflow in the showQueryPackage function in librpm in RPM Package Manager 4.4.8, when the LANG environment variable is set to ru_RU.UTF-8…
PriorityP427medium5.4CVSS 2.0
AVNACHAuNCNINAC
EPSS
3.58%
88.1th percentile
Heap-based buffer overflow in the showQueryPackage function in librpm in RPM Package Manager 4.4.8, when the LANG environment variable is set to ru_RU.UTF-8, might allow user-assisted attackers to execute arbitrary code via crafted RPM packages.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | rpm | < rpm 4.4.1-11 (bookworm) | rpm 4.4.1-11 (bookworm) |
| rpm | package_manager | — | — |
| rpm | rpm | >= 0 < 4.4.1-11 | 4.4.1-11 |
| rpm | rpm | >= 0 < 4.4.1-11 | 4.4.1-11 |
| rpm | rpm | >= 0 < 4.4.1-11 | 4.4.1-11 |
| rpm | rpm | >= 0 < 4.4.1-11 | 4.4.1-11 |
| ubuntu | ubuntu_linux | — | — |
| ubuntu | ubuntu_linux | — | — |
CVSS provenance
nvdv2.05.4MEDIUMAV:N/AC:H/Au:N/C:N/I:N/A:C
osv5.4MEDIUM
vendor_debian5.4LOW
vendor_redhat5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r6mw-vx2r-6ppm: Heap-based buffer overflow in the showQueryPackage function in librpm in RPM Package Manager 4
ghsa_unreviewed·2022-05-01
CVE-2006-5466 [MEDIUM] GHSA-r6mw-vx2r-6ppm: Heap-based buffer overflow in the showQueryPackage function in librpm in RPM Package Manager 4
Heap-based buffer overflow in the showQueryPackage function in librpm in RPM Package Manager 4.4.8, when the LANG environment variable is set to ru_RU.UTF-8, might allow user-assisted attackers to execute arbitrary code via crafted RPM packages.
OSV
CVE-2006-5466: Heap-based buffer overflow in the showQueryPackage function in librpm in RPM Package Manager 4
osv·2006-11-06·CVSS 5.4
CVE-2006-5466 [MEDIUM] CVE-2006-5466: Heap-based buffer overflow in the showQueryPackage function in librpm in RPM Package Manager 4
Heap-based buffer overflow in the showQueryPackage function in librpm in RPM Package Manager 4.4.8, when the LANG environment variable is set to ru_RU.UTF-8, might allow user-assisted attackers to execute arbitrary code via crafted RPM packages.
Ubuntu
RPM vulnerability
vendor_ubuntu·2006-11-04
CVE-2006-5466 RPM vulnerability
Title: RPM vulnerability
Summary: RPM vulnerability
An error was found in the RPM library's handling of query reports. In
some locales, certain RPM packages would cause the library to crash. If
a user was tricked into querying a specially crafted RPM package, the
flaw could be exploited to execute arbitrary code with the user's
privileges.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Red Hat
RPM Crash after listing contents of non-installed package
vendor_redhat·2006-10-29·CVSS 5.4
CVE-2006-5466 [MEDIUM] RPM Crash after listing contents of non-installed package
RPM Crash after listing contents of non-installed package
Heap-based buffer overflow in the showQueryPackage function in librpm in RPM Package Manager 4.4.8, when the LANG environment variable is set to ru_RU.UTF-8, might allow user-assisted attackers to execute arbitrary code via crafted RPM packages.
Statement: Red Hat non longer plans to fix this flaw in Red Hat Enterprise Linux 4.
Debian
CVE-2006-5466: rpm - Heap-based buffer overflow in the showQueryPackage function in librpm in RPM Pac...
vendor_debian·2006·CVSS 5.4
CVE-2006-5466 [MEDIUM] CVE-2006-5466: rpm - Heap-based buffer overflow in the showQueryPackage function in librpm in RPM Pac...
Heap-based buffer overflow in the showQueryPackage function in librpm in RPM Package Manager 4.4.8, when the LANG environment variable is set to ru_RU.UTF-8, might allow user-assisted attackers to execute arbitrary code via crafted RPM packages.
Scope: local
bookworm: resolved (fixed in 4.4.1-11)
bullseye: resolved (fixed in 4.4.1-11)
forky: resolved (fixed in 4.4.1-11)
sid: resolved (fixed in 4.4.1-11)
trixie: resolved (fixed in 4.4.1-11)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2006-5466 RPM Crash after listing contents of non-installed package
bugzilla·2006-11-01·CVSS 5.4
CVE-2006-5466 [MEDIUM] CVE-2006-5466 RPM Crash after listing contents of non-installed package
CVE-2006-5466 RPM Crash after listing contents of non-installed package
+++ This bug was initially created as a clone of Bug #212833 +++
From Bugzilla Helper:
User-Agent: Mozilla/5.0 (X11; U; Linux x86_64; ru; rv:1.8.0.7) Gecko/20061011
Fedora/1.5.0.7-7.fc6 Firefox/1.5.0.7
Description of problem:
RPM crashes when trying to show info/listing/changelog of sylpheed-claws package
from extras.
Version-Release number of selected component (if applicable):
rpm-4.4.2-32.x86_64
How reproducible:
Always
Steps to Reproduce:
1. Download sylpheed-claws package "wget
http://redhat.download.fedoraproject.org/pub/fedora/linux/extras/6/x86_64/sylpheed-claws-2.5.6-1.fc6.x86_64.rpm"
2. Do "rpm -qipvl --changelog sylpheed-claws-2.5.6-1.fc6.x86_64.rpm"
3. Observe the crash after last file from package i
Bugzilla
CVE-2006-5466 RPM Crash after listing contents of non-installed package
bugzilla·2006-10-29·CVSS 5.4
CVE-2006-5466 [MEDIUM] CVE-2006-5466 RPM Crash after listing contents of non-installed package
CVE-2006-5466 RPM Crash after listing contents of non-installed package
From Bugzilla Helper:
User-Agent: Mozilla/5.0 (X11; U; Linux x86_64; ru; rv:1.8.0.7) Gecko/20061011 Fedora/1.5.0.7-7.fc6 Firefox/1.5.0.7
Description of problem:
RPM crashes when trying to show info/listing/changelog of sylpheed-claws package from extras.
Version-Release number of selected component (if applicable):
rpm-4.4.2-32.x86_64
How reproducible:
Always
Steps to Reproduce:
1. Download sylpheed-claws package "wget http://redhat.download.fedoraproject.org/pub/fedora/linux/extras/6/x86_64/sylpheed-claws-2.5.6-1.fc6.x86_64.rpm"
2. Do "rpm -qipvl --changelog sylpheed-claws-2.5.6-1.fc6.x86_64.rpm"
3. Observe the crash after last file from package is listed
Actual Results:
*** glibc detected *** /usr/lib/rpm/rpmq
http://secunia.com/advisories/22740http://secunia.com/advisories/22745http://secunia.com/advisories/22768http://secunia.com/advisories/22854http://security.gentoo.org/glsa/glsa-200611-08.xmlhttp://securitytracker.com/id?1017160http://www.mandriva.com/security/advisories?name=MDKSA-2006:200http://www.securityfocus.com/bid/20906http://www.ubuntu.com/usn/usn-378-1http://www.vupen.com/english/advisories/2006/4350https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=212833http://secunia.com/advisories/22740http://secunia.com/advisories/22745http://secunia.com/advisories/22768http://secunia.com/advisories/22854http://security.gentoo.org/glsa/glsa-200611-08.xmlhttp://securitytracker.com/id?1017160http://www.mandriva.com/security/advisories?name=MDKSA-2006:200http://www.securityfocus.com/bid/20906http://www.ubuntu.com/usn/usn-378-1http://www.vupen.com/english/advisories/2006/4350https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=212833
2006-11-06
Published