CVE-2012-0061
published 2012-06-04CVE-2012-0061: The headerLoad function in lib/header.c in RPM before 4.9.1.3 does not properly validate region tags, which allows user-assisted remote attackers to cause a…
PriorityP431medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
4.38%
90.2th percentile
The headerLoad function in lib/header.c in RPM before 4.9.1.3 does not properly validate region tags, which allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large region size in a package header.
Affected
103 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | rpm | < rpm 4.9.1.3-1 (bookworm) | rpm 4.9.1.3-1 (bookworm) |
| rpm | rpm | <= 4.9.1.2 | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_redhat6.9MEDIUM
vendor_debian6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v3v4-hffr-vr89: The headerLoad function in lib/header
ghsa_unreviewed·2022-05-04
CVE-2012-0061 [MEDIUM] CWE-20 GHSA-v3v4-hffr-vr89: The headerLoad function in lib/header
The headerLoad function in lib/header.c in RPM before 4.9.1.3 does not properly validate region tags, which allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large region size in a package header.
OSV
CVE-2012-0061: The headerLoad function in lib/header
osv·2012-06-04·CVSS 6.8
CVE-2012-0061 [MEDIUM] CVE-2012-0061: The headerLoad function in lib/header
The headerLoad function in lib/header.c in RPM before 4.9.1.3 does not properly validate region tags, which allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large region size in a package header.
Ubuntu
RPM vulnerabilities
vendor_ubuntu·2013-01-17
CVE-2011-3378 RPM vulnerabilities
Title: RPM vulnerabilities
Summary: RPM could be made to crash or run programs if it opened a specially crafted
package file.
It was discovered that RPM incorrectly handled certain package headers. If
a user or automated system were tricked into installing a specially crafted
RPM package, an attacker could cause RPM to crash, resulting in a denial of
service, or possibly execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
rpm: improper validation of header contents total size in headerLoad()
vendor_redhat·2012-04-03·CVSS 6.8
CVE-2012-0061 [MEDIUM] CWE-228 rpm: improper validation of header contents total size in headerLoad()
rpm: improper validation of header contents total size in headerLoad()
The headerLoad function in lib/header.c in RPM before 4.9.1.3 does not properly validate region tags, which allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large region size in a package header.
Red Hat
kernel: proc: /proc/<pid>/mem mem_write insufficient permission checking
vendor_redhat·2012-01-18·CVSS 6.9
CVE-2012-0056 [MEDIUM] CWE-863 kernel: proc: /proc/<pid>/mem mem_write insufficient permission checking
kernel: proc: /proc//mem mem_write insufficient permission checking
The mem_write function in the Linux kernel before 3.2.2, when ASLR is disabled, does not properly check permissions when writing to /proc//mem, which allows local users to gain privileges by modifying process memory, as demonstrated by Mempodipper.
Statement: This issue did not affect the version of Linux kernel as shipped with Red Hat Enterprise Linux 4 and 5 as it did not backport the upstream commit 198214a7ee. This has been addressed in Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG via https://rhn.redhat.com/errata/RHSA-2012-0052.html and https://rhn.redhat.com/errata/RHSA-2012-0061.html. For more information, please read https://access.redhat.com/kb/docs/DOC-69129.
Package: kernel (Red Hat Enterprise Linux
Debian
CVE-2012-0061: rpm - The headerLoad function in lib/header.c in RPM before 4.9.1.3 does not properly ...
vendor_debian·2012·CVSS 6.8
CVE-2012-0061 [MEDIUM] CVE-2012-0061: rpm - The headerLoad function in lib/header.c in RPM before 4.9.1.3 does not properly ...
The headerLoad function in lib/header.c in RPM before 4.9.1.3 does not properly validate region tags, which allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large region size in a package header.
Scope: local
bookworm: resolved (fixed in 4.9.1.3-1)
bullseye: resolved (fixed in 4.9.1.3-1)
forky: resolved (fixed in 4.9.1.3-1)
sid: resolved (fixed in 4.9.1.3-1)
trixie: resolved (fixed in 4.9.1.3-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-5471 moodle: Various security issues fixed in upstream 2.3.3, 2.2.6 and 2.1.9 versions (MSA-12-0057, MSA-12-0058, MSA-12-0059, MSA-12-0060, MSA-12-0061, MSA-12-0062, MSA-12-0063) [fedora-all]
bugzilla·2012-11-19·CVSS 6.5
CVE-2012-5471 [MEDIUM] CVE-2012-5471 moodle: Various security issues fixed in upstream 2.3.3, 2.2.6 and 2.1.9 versions (MSA-12-0057, MSA-12-0058, MSA-12-0059, MSA-12-0060, MSA-12-0061, MSA-12-0062, MSA-12-0063) [fedora-all]
CVE-2012-5471 moodle: Various security issues fixed in upstream 2.3.3, 2.2.6 and 2.1.9 versions (MSA-12-0057, MSA-12-0058, MSA-12-0059, MSA-12-0060, MSA-12-0061, MSA-12-0062, MSA-12-0063) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also
Bugzilla
CVE-2012-0815 CVE-2012-0060 CVE-2012-0061 rpm various flaws [fedora-all]
bugzilla·2012-04-03·CVSS 6.8
CVE-2012-0815 [MEDIUM] CVE-2012-0815 CVE-2012-0060 CVE-2012-0061 rpm various flaws [fedora-all]
CVE-2012-0815 CVE-2012-0060 CVE-2012-0061 rpm various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bu
Bugzilla
CVE-2012-0061 rpm: improper validation of header contents total size in headerLoad()
bugzilla·2012-02-29·CVSS 6.8
CVE-2012-0061 [MEDIUM] CVE-2012-0061 rpm: improper validation of header contents total size in headerLoad()
CVE-2012-0061 rpm: improper validation of header contents total size in headerLoad()
It was discovered that RPM did not properly validate region size in headerLoad() when loading header from an RPM file, allowing region size to exceed containing header size. A malformed or malicious RPM file could cause RPM to crash and possibly execute arbitrary code before file signature was properly verified.
Upstream commits:
http://rpm.org/gitweb?p=rpm.git;a=commitdiff;h=472e569562d4c90d7a298080e0052856aa7fa86b
http://rpm.org/gitweb?p=rpm.git;a=commitdiff;h=858a328cd0f7d4bcd8500c78faaf00e4f8033df6
Discussion:
Created attachment 566511
RPM 4.8.x patch
---
Created attachment 566512
RPM 4.4.x patch
---
Lifting embargo. Fix is already in upstream git:
http://rpm.org/gitweb?p=rpm.git;a=commitdiff;
http://lists.fedoraproject.org/pipermail/package-announce/2012-April/077960.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-April/078819.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-April/078907.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0451.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0531.htmlhttp://rpm.org/gitweb?p=rpm.git%3Ba=commitdiff%3Bh=472e569562d4c90d7a298080e0052856aa7fa86bhttp://rpm.org/gitweb?p=rpm.git%3Ba=commitdiff%3Bh=858a328cd0f7d4bcd8500c78faaf00e4f8033df6http://rpm.org/wiki/Releases/4.9.1.3http://secunia.com/advisories/48651http://secunia.com/advisories/48716http://secunia.com/advisories/49110http://www.mandriva.com/security/advisories?name=MDVSA-2012:056http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.osvdb.org/81010http://www.securityfocus.com/bid/52865http://www.securitytracker.com/id?1026882http://www.ubuntu.com/usn/USN-1695-1https://bugzilla.redhat.com/show_bug.cgi?id=798585https://exchange.xforce.ibmcloud.com/vulnerabilities/74583https://hermes.opensuse.org/messages/14440932https://hermes.opensuse.org/messages/14441362http://lists.fedoraproject.org/pipermail/package-announce/2012-April/077960.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-April/078819.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-April/078907.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0451.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0531.htmlhttp://rpm.org/gitweb?p=rpm.git%3Ba=commitdiff%3Bh=472e569562d4c90d7a298080e0052856aa7fa86bhttp://rpm.org/gitweb?p=rpm.git%3Ba=commitdiff%3Bh=858a328cd0f7d4bcd8500c78faaf00e4f8033df6http://rpm.org/wiki/Releases/4.9.1.3http://secunia.com/advisories/48651http://secunia.com/advisories/48716http://secunia.com/advisories/49110http://www.mandriva.com/security/advisories?name=MDVSA-2012:056http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.osvdb.org/81010http://www.securityfocus.com/bid/52865http://www.securitytracker.com/id?1026882http://www.ubuntu.com/usn/USN-1695-1https://bugzilla.redhat.com/show_bug.cgi?id=798585https://exchange.xforce.ibmcloud.com/vulnerabilities/74583https://hermes.opensuse.org/messages/14440932https://hermes.opensuse.org/messages/14441362
2012-06-04
Published