CVE-2012-0060
published 2012-06-04CVE-2012-0060: RPM before 4.9.1.3 does not properly validate region tags, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary…
PriorityP335medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
4.78%
90.9th percentile
RPM before 4.9.1.3 does not properly validate region tags, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an invalid region tag in a package header to the (1) headerLoad, (2) rpmReadSignature, or (3) headerVerify function.
Affected
103 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | rpm | < rpm 4.9.1.3-1 (bookworm) | rpm 4.9.1.3-1 (bookworm) |
| rpm | rpm | <= 4.9.1.2 | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
RPM vulnerabilities
vendor_ubuntu·2013-01-17
CVE-2011-3378 RPM vulnerabilities
Title: RPM vulnerabilities
Summary: RPM could be made to crash or run programs if it opened a specially crafted
package file.
It was discovered that RPM incorrectly handled certain package headers. If
a user or automated system were tricked into installing a specially crafted
RPM package, an attacker could cause RPM to crash, resulting in a denial of
service, or possibly execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
rpm: insufficient validation of region tags
vendor_redhat·2012-04-03·CVSS 6.8
CVE-2012-0060 [MEDIUM] CWE-228 rpm: insufficient validation of region tags
rpm: insufficient validation of region tags
RPM before 4.9.1.3 does not properly validate region tags, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an invalid region tag in a package header to the (1) headerLoad, (2) rpmReadSignature, or (3) headerVerify function.
Debian
CVE-2012-0060: rpm - RPM before 4.9.1.3 does not properly validate region tags, which allows remote a...
vendor_debian·2012·CVSS 6.8
CVE-2012-0060 [MEDIUM] CVE-2012-0060: rpm - RPM before 4.9.1.3 does not properly validate region tags, which allows remote a...
RPM before 4.9.1.3 does not properly validate region tags, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an invalid region tag in a package header to the (1) headerLoad, (2) rpmReadSignature, or (3) headerVerify function.
Scope: local
bookworm: resolved (fixed in 4.9.1.3-1)
bullseye: resolved (fixed in 4.9.1.3-1)
forky: resolved (fixed in 4.9.1.3-1)
sid: resolved (fixed in 4.9.1.3-1)
trixie: resolved (fixed in 4.9.1.3-1)
GHSA
GHSA-j6wj-cqmg-hvcm: RPM before 4
ghsa_unreviewed·2022-05-04
CVE-2012-0060 [MEDIUM] CWE-20 GHSA-j6wj-cqmg-hvcm: RPM before 4
RPM before 4.9.1.3 does not properly validate region tags, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an invalid region tag in a package header to the (1) headerLoad, (2) rpmReadSignature, or (3) headerVerify function.
Kernel
KVM: x86: invalid opcode oops on SET_SREGS with OSXSAVE bit set (CVE-2012-4461)
kernel_security·2012-11-06·CVSS 1.9
CVE-2012-4461 [LOW] KVM: x86: invalid opcode oops on SET_SREGS with OSXSAVE bit set (CVE-2012-4461)
KVM: x86: invalid opcode oops on SET_SREGS with OSXSAVE bit set (CVE-2012-4461)
On hosts without the XSAVE support unprivileged local user can trigger
oops similar to the one below by setting X86_CR4_OSXSAVE bit in guest
cr4 register using KVM_SET_SREGS ioctl and later issuing KVM_RUN
ioctl.
invalid opcode: 0000 [#2] SMP
Modules linked in: tun ip6table_filter ip6_tables ebtable_nat ebtables
...
Pid: 24935, comm: zoog_kvm_monito Tainted: G D 3.2.0-3-686-pae
EIP: 0060:[] EFLAGS: 00210246 CPU: 0
EIP is at kvm_arch_vcpu_ioctl_run+0x92a/0xd13 [kvm]
EAX: 00000001 EBX: 000f387e ECX: 00000000 EDX: 00000000
ESI: 00000000 EDI: 00000000 EBP: ef5a0060 ESP: d7c63e70
DS: 007b ES: 007b FS: 00d8 GS: 00e0 SS: 0068
Process zoog_kvm_monito (pid: 24935, ti=d7c62000 task=ed84a0c0
task.ti=d7c62000)
Stack:
000
OSV
CVE-2012-0060: RPM before 4
osv·2012-06-04·CVSS 6.8
CVE-2012-0060 [MEDIUM] CVE-2012-0060: RPM before 4
RPM before 4.9.1.3 does not properly validate region tags, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an invalid region tag in a package header to the (1) headerLoad, (2) rpmReadSignature, or (3) headerVerify function.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-5471 moodle: Various security issues fixed in upstream 2.3.3, 2.2.6 and 2.1.9 versions (MSA-12-0057, MSA-12-0058, MSA-12-0059, MSA-12-0060, MSA-12-0061, MSA-12-0062, MSA-12-0063) [fedora-all]
bugzilla·2012-11-19·CVSS 6.5
CVE-2012-5471 [MEDIUM] CVE-2012-5471 moodle: Various security issues fixed in upstream 2.3.3, 2.2.6 and 2.1.9 versions (MSA-12-0057, MSA-12-0058, MSA-12-0059, MSA-12-0060, MSA-12-0061, MSA-12-0062, MSA-12-0063) [fedora-all]
CVE-2012-5471 moodle: Various security issues fixed in upstream 2.3.3, 2.2.6 and 2.1.9 versions (MSA-12-0057, MSA-12-0058, MSA-12-0059, MSA-12-0060, MSA-12-0061, MSA-12-0062, MSA-12-0063) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also
Bugzilla
CVE-2012-2373 kernel: mm: read_pmd_atomic: 32bit PAE pmd walk vs pmd_populate SMP race condition
bugzilla·2012-05-18·CVSS 4.0
CVE-2012-2373 [MEDIUM] CVE-2012-2373 kernel: mm: read_pmd_atomic: 32bit PAE pmd walk vs pmd_populate SMP race condition
CVE-2012-2373 kernel: mm: read_pmd_atomic: 32bit PAE pmd walk vs pmd_populate SMP race condition
When holding the mmap_sem for reading, pmd_offset_map_lock should only
run on a pmd_t that has been read atomically from the pmdp
pointer, otherwise we may read only half of it leading to this crash.
PID: 11679 TASK: f06e8000 CPU: 3 COMMAND: "do_race_2_panic"
#0 [f06a9dd8] crash_kexec at c049b5ec
#1 [f06a9e2c] oops_end at c083d1c2
#2 [f06a9e40] no_context at c0433ded
#3 [f06a9e64] bad_area_nosemaphore at c043401a
#4 [f06a9e6c] __do_page_fault at c0434493
#5 [f06a9eec] do_page_fault at c083eb45
#6 [f06a9f04] error_code (via page_fault) at c083c5d5
EAX: 01fb470c EBX: fff35000 ECX: 00000003 EDX: 00000100 EBP:
00000000
DS: 007b ESI: 9e201000 ES: 007b EDI: 01fb4700 GS: 00e0
CS: 0060 EIP: c083bc14
Bugzilla
CVE-2012-0815 CVE-2012-0060 CVE-2012-0061 rpm various flaws [fedora-all]
bugzilla·2012-04-03·CVSS 6.8
CVE-2012-0815 [MEDIUM] CVE-2012-0815 CVE-2012-0060 CVE-2012-0061 rpm various flaws [fedora-all]
CVE-2012-0815 CVE-2012-0060 CVE-2012-0061 rpm various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bu
Bugzilla
CVE-2011-4109 openssl: double-free in policy checks
bugzilla·2012-01-04·CVSS 9.3
CVE-2011-4109 [CRITICAL] CVE-2011-4109 openssl: double-free in policy checks
CVE-2011-4109 openssl: double-free in policy checks
Double-free in Policy Checks (CVE-2011-4109)
If X509_V_FLAG_POLICY_CHECK is set in OpenSSL 0.9.8, then a policy
check failure can lead to a double-free. The bug does not occur
unless this flag is set. Users of OpenSSL 1.0.0 are not affected.
This flaw was discovered by Ben Laurie and a fix provided by Emilia
Kasper of Google.
Affected users should upgrade to OpenSSL 0.9.8s.
Reference: http://openssl.org/news/secadv_20120104.txt
Discussion:
Seems to be the fix here:
http://cvs.openssl.org/chngview?cn=21941
---
Created mingw32-openssl tracking bugs for this issue
Affects: epel-5 [bug 773331]
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2012:0060 https://rhn.redhat.com/errata/RHS
Bugzilla
CVE-2012-0060 rpm: insufficient validation of region tags
bugzilla·2011-10-10·CVSS 6.8
CVE-2012-0060 [MEDIUM] CVE-2012-0060 rpm: insufficient validation of region tags
CVE-2012-0060 rpm: insufficient validation of region tags
Multiple improper input validation flaws were found in the code for handling region tags within headerLoad, rpmReadSignature and headerVerify functions of RPM library. These functions are used by rpm utility to read the signature header section and verify the values of header structures (i.e. signature and header sections) of a RPM file respectively. An attacker could create a specially-crafted RPM file that, when read, could cause RPM to crash or, potentially, execute arbitrary code.
Discussion:
Created attachment 566531
RPM 4.8.x patch - headerLoad
---
Created attachment 566532
RPM 4.8.x patch - headerVerify and rpmReadSignature
---
Created attachment 566535
RPM 4.4.x patch - headerLoad
---
Created attachment 566536
RPM 4
http://lists.fedoraproject.org/pipermail/package-announce/2012-April/077960.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-April/078819.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-April/078907.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0451.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0531.htmlhttp://rpm.org/gitweb?p=rpm.git%3Ba=commitdiff%3Bh=e4eab2bc6d07cfd33f740071de7ddbb2fe2f4190http://rpm.org/gitweb?p=rpm.git%3Ba=commitdiff%3Bh=f23998251992b8ae25faf5113c42fee2c49c7f29http://rpm.org/wiki/Releases/4.9.1.3http://secunia.com/advisories/48651http://secunia.com/advisories/48716http://secunia.com/advisories/49110http://www.mandriva.com/security/advisories?name=MDVSA-2012:056http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.osvdb.org/81010http://www.securityfocus.com/bid/52865http://www.securitytracker.com/id?1026882http://www.ubuntu.com/usn/USN-1695-1https://bugzilla.redhat.com/show_bug.cgi?id=744858https://exchange.xforce.ibmcloud.com/vulnerabilities/74582https://hermes.opensuse.org/messages/14440932https://hermes.opensuse.org/messages/14441362http://lists.fedoraproject.org/pipermail/package-announce/2012-April/077960.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-April/078819.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-April/078907.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0451.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0531.htmlhttp://rpm.org/gitweb?p=rpm.git%3Ba=commitdiff%3Bh=e4eab2bc6d07cfd33f740071de7ddbb2fe2f4190http://rpm.org/gitweb?p=rpm.git%3Ba=commitdiff%3Bh=f23998251992b8ae25faf5113c42fee2c49c7f29http://rpm.org/wiki/Releases/4.9.1.3http://secunia.com/advisories/48651http://secunia.com/advisories/48716http://secunia.com/advisories/49110http://www.mandriva.com/security/advisories?name=MDVSA-2012:056http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.osvdb.org/81010http://www.securityfocus.com/bid/52865http://www.securitytracker.com/id?1026882http://www.ubuntu.com/usn/USN-1695-1https://bugzilla.redhat.com/show_bug.cgi?id=744858https://exchange.xforce.ibmcloud.com/vulnerabilities/74582https://hermes.opensuse.org/messages/14440932https://hermes.opensuse.org/messages/14441362
2012-06-04
Published