cbcvebase.
CVE-2006-5466
published 2006-11-06

CVE-2006-5466: Heap-based buffer overflow in the showQueryPackage function in librpm in RPM Package Manager 4.4.8, when the LANG environment variable is set to ru_RU.UTF-8…

PriorityP427medium5.4CVSS 2.0
AVNACHAuNCNINAC
EPSS
3.58%
88.1th percentile
Heap-based buffer overflow in the showQueryPackage function in librpm in RPM Package Manager 4.4.8, when the LANG environment variable is set to ru_RU.UTF-8, might allow user-assisted attackers to execute arbitrary code via crafted RPM packages.

Affected

8 ranges
VendorProductVersion rangeFixed in
debianrpm< rpm 4.4.1-11 (bookworm)rpm 4.4.1-11 (bookworm)
rpmpackage_manager
rpmrpm>= 0 < 4.4.1-114.4.1-11
rpmrpm>= 0 < 4.4.1-114.4.1-11
rpmrpm>= 0 < 4.4.1-114.4.1-11
rpmrpm>= 0 < 4.4.1-114.4.1-11
ubuntuubuntu_linux
ubuntuubuntu_linux

CVSS provenance

nvdv2.05.4MEDIUMAV:N/AC:H/Au:N/C:N/I:N/A:C
osv5.4MEDIUM
vendor_debian5.4LOW
vendor_redhat5.4MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.