CVE-2011-3378
published 2011-12-24CVE-2011-3378: RPM 4.4.x through 4.9.x, probably before 4.9.1.2, allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code…
PriorityP343critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
6.04%
92.6th percentile
RPM 4.4.x through 4.9.x, probably before 4.9.1.2, allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via an rpm package with crafted headers and offsets that are not properly handled when a package is queried or installed, related to (1) the regionSwab function, (2) the headerLoad function, and (3) multiple functions in rpmio/rpmpgp.c.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | rpm | < rpm 4.9.1.2-1 (bookworm) | rpm 4.9.1.2-1 (bookworm) |
| rpm | rpm | <= 4.9.1.1 | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | >= 0 < 4.9.1.2-1 | 4.9.1.2-1 |
| rpm | rpm | >= 0 < 4.9.1.2-1 | 4.9.1.2-1 |
| rpm | rpm | >= 0 < 4.9.1.2-1 | 4.9.1.2-1 |
| rpm | rpm | >= 0 < 4.9.1.2-1 | 4.9.1.2-1 |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_debian9.3LOW
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-34ff-v8wx-w9f5: RPM 4
ghsa_unreviewed·2022-05-17
CVE-2011-3378 [HIGH] CWE-94 GHSA-34ff-v8wx-w9f5: RPM 4
RPM 4.4.x through 4.9.x, probably before 4.9.1.2, allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via an rpm package with crafted headers and offsets that are not properly handled when a package is queried or installed, related to (1) the regionSwab function, (2) the headerLoad function, and (3) multiple functions in rpmio/rpmpgp.c.
OSV
CVE-2011-3378: RPM 4
osv·2011-12-24·CVSS 9.3
CVE-2011-3378 [CRITICAL] CVE-2011-3378: RPM 4
RPM 4.4.x through 4.9.x, probably before 4.9.1.2, allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via an rpm package with crafted headers and offsets that are not properly handled when a package is queried or installed, related to (1) the regionSwab function, (2) the headerLoad function, and (3) multiple functions in rpmio/rpmpgp.c.
Ubuntu
RPM vulnerabilities
vendor_ubuntu·2013-01-17
CVE-2011-3378 RPM vulnerabilities
Title: RPM vulnerabilities
Summary: RPM could be made to crash or run programs if it opened a specially crafted
package file.
It was discovered that RPM incorrectly handled certain package headers. If
a user or automated system were tricked into installing a specially crafted
RPM package, an attacker could cause RPM to crash, resulting in a denial of
service, or possibly execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
rpm: crashes and overflows on malformed header
vendor_redhat·2011-09-27·CVSS 9.3
CVE-2011-3378 [CRITICAL] CWE-228 rpm: crashes and overflows on malformed header
rpm: crashes and overflows on malformed header
RPM 4.4.x through 4.9.x, probably before 4.9.1.2, allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via an rpm package with crafted headers and offsets that are not properly handled when a package is queried or installed, related to (1) the regionSwab function, (2) the headerLoad function, and (3) multiple functions in rpmio/rpmpgp.c.
Debian
CVE-2011-3378: rpm - RPM 4.4.x through 4.9.x, probably before 4.9.1.2, allows remote attackers to cau...
vendor_debian·2011·CVSS 9.3
CVE-2011-3378 [CRITICAL] CVE-2011-3378: rpm - RPM 4.4.x through 4.9.x, probably before 4.9.1.2, allows remote attackers to cau...
RPM 4.4.x through 4.9.x, probably before 4.9.1.2, allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via an rpm package with crafted headers and offsets that are not properly handled when a package is queried or installed, related to (1) the regionSwab function, (2) the headerLoad function, and (3) multiple functions in rpmio/rpmpgp.c.
Scope: local
bookworm: resolved (fixed in 4.9.1.2-1)
bullseye: resolved (fixed in 4.9.1.2-1)
forky: resolved (fixed in 4.9.1.2-1)
sid: resolved (fixed in 4.9.1.2-1)
trixie: resolved (fixed in 4.9.1.2-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-3378 rpm: crashes and overflows on malformed header [fedora-all]
bugzilla·2011-10-03·CVSS 9.3
CVE-2011-3378 [CRITICAL] CVE-2011-3378 rpm: crashes and overflows on malformed header [fedora-all]
CVE-2011-3378 rpm: crashes and overflows on malformed header [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=741606
Please note: this issue affects multiple
Bugzilla
CVE-2011-3378 rpm: crashes and overflows on malformed header
bugzilla·2011-09-27·CVSS 9.3
CVE-2011-3378 [CRITICAL] CVE-2011-3378 rpm: crashes and overflows on malformed header
CVE-2011-3378 rpm: crashes and overflows on malformed header
Created attachment 525110
testcase
Description of problem:
int off = ntohl(pe->offset);
if (hdrchkData(off))
goto errxit;
if (off) {
size_t nb = REGION_TAG_COUNT;
int32_t stei[nb];
/* XXX Hmm, why the copy? */
memcpy(&stei, dataStart + off, nb);
No check for dataStart + off > dataEnd.
(gdb) r --checksig rpminput.rpm
[Thread debugging using libthread_db enabled]
Using host libthread_db library "/lib/libthread_db.so.1".
error: no dbpath has been set
error: cannot open Packages database in /%{_dbpath}
Program received signal SIGSEGV, Segmentation fault.
memcpy () at ../sysdeps/x86_64/memcpy.S:117
117 ../sysdeps/x86_64/memcpy.S: No such file or directory.
in ../sysdeps/x86_64/memcpy.S
(gdb) bt
#0 memcpy () at ../sysdeps/x86_64
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10691http://lists.opensuse.org/opensuse-security-announce/2011-11/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-11/msg00002.htmlhttp://rpm.org/gitweb?p=rpm.git%3Ba=commitdiff%3Bh=11a7e5d95a8ca8c7d4eaff179094afd8bb74fc3fhttp://rpm.org/gitweb?p=rpm.git%3Ba=commitdiff%3Bh=a48f0e20cbe2ababc88b2fc52fb7a281d6fc1656http://rpm.org/wiki/Releases/4.9.1.2#Securityhttp://www.mandriva.com/security/advisories?name=MDVSA-2011:143http://www.openwall.com/lists/oss-security/2011/09/27/3http://www.redhat.com/support/errata/RHSA-2011-1349.htmlhttp://www.ubuntu.com/usn/USN-1695-1https://bugzilla.redhat.com/show_bug.cgi?id=741606https://bugzilla.redhat.com/show_bug.cgi?id=741612http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10691http://lists.opensuse.org/opensuse-security-announce/2011-11/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-11/msg00002.htmlhttp://rpm.org/gitweb?p=rpm.git%3Ba=commitdiff%3Bh=11a7e5d95a8ca8c7d4eaff179094afd8bb74fc3fhttp://rpm.org/gitweb?p=rpm.git%3Ba=commitdiff%3Bh=a48f0e20cbe2ababc88b2fc52fb7a281d6fc1656http://rpm.org/wiki/Releases/4.9.1.2#Securityhttp://www.mandriva.com/security/advisories?name=MDVSA-2011:143http://www.openwall.com/lists/oss-security/2011/09/27/3http://www.redhat.com/support/errata/RHSA-2011-1349.htmlhttp://www.ubuntu.com/usn/USN-1695-1https://bugzilla.redhat.com/show_bug.cgi?id=741606https://bugzilla.redhat.com/show_bug.cgi?id=741612
2011-12-24
Published