CVE-2012-0815
published 2012-06-04CVE-2012-0815: The headerVerifyInfo function in lib/header.c in RPM before 4.9.1.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary…
PriorityP334medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
4.28%
90.0th percentile
The headerVerifyInfo function in lib/header.c in RPM before 4.9.1.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a negative value in a region offset of a package header, which is not properly handled in a numeric range comparison.
Affected
103 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | rpm | < rpm 4.9.1.3-1 (bookworm) | rpm 4.9.1.3-1 (bookworm) |
| rpm | rpm | <= 4.9.1.2 | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
RPM vulnerabilities
vendor_ubuntu·2013-01-17
CVE-2011-3378 RPM vulnerabilities
Title: RPM vulnerabilities
Summary: RPM could be made to crash or run programs if it opened a specially crafted
package file.
It was discovered that RPM incorrectly handled certain package headers. If
a user or automated system were tricked into installing a specially crafted
RPM package, an attacker could cause RPM to crash, resulting in a denial of
service, or possibly execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
rpm: incorrect handling of negated offsets in headerVerifyInfo()
vendor_redhat·2012-04-03·CVSS 6.8
CVE-2012-0815 [MEDIUM] CWE-839 rpm: incorrect handling of negated offsets in headerVerifyInfo()
rpm: incorrect handling of negated offsets in headerVerifyInfo()
The headerVerifyInfo function in lib/header.c in RPM before 4.9.1.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a negative value in a region offset of a package header, which is not properly handled in a numeric range comparison.
Debian
CVE-2012-0815: rpm - The headerVerifyInfo function in lib/header.c in RPM before 4.9.1.3 allows remot...
vendor_debian·2012·CVSS 6.8
CVE-2012-0815 [MEDIUM] CVE-2012-0815: rpm - The headerVerifyInfo function in lib/header.c in RPM before 4.9.1.3 allows remot...
The headerVerifyInfo function in lib/header.c in RPM before 4.9.1.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a negative value in a region offset of a package header, which is not properly handled in a numeric range comparison.
Scope: local
bookworm: resolved (fixed in 4.9.1.3-1)
bullseye: resolved (fixed in 4.9.1.3-1)
forky: resolved (fixed in 4.9.1.3-1)
sid: resolved (fixed in 4.9.1.3-1)
trixie: resolved (fixed in 4.9.1.3-1)
GHSA
GHSA-6grx-55mc-2wmq: The headerVerifyInfo function in lib/header
ghsa_unreviewed·2022-05-14
CVE-2012-0815 [MEDIUM] GHSA-6grx-55mc-2wmq: The headerVerifyInfo function in lib/header
The headerVerifyInfo function in lib/header.c in RPM before 4.9.1.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a negative value in a region offset of a package header, which is not properly handled in a numeric range comparison.
OSV
CVE-2012-0815: The headerVerifyInfo function in lib/header
osv·2012-06-04·CVSS 6.8
CVE-2012-0815 [MEDIUM] CVE-2012-0815: The headerVerifyInfo function in lib/header
The headerVerifyInfo function in lib/header.c in RPM before 4.9.1.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a negative value in a region offset of a package header, which is not properly handled in a numeric range comparison.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-0815 CVE-2012-0060 CVE-2012-0061 rpm various flaws [fedora-all]
bugzilla·2012-04-03·CVSS 6.8
CVE-2012-0815 [MEDIUM] CVE-2012-0815 CVE-2012-0060 CVE-2012-0061 rpm various flaws [fedora-all]
CVE-2012-0815 CVE-2012-0060 CVE-2012-0061 rpm various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bu
Bugzilla
CVE-2012-0815 rpm: incorrect handling of negated offsets in headerVerifyInfo()
bugzilla·2011-10-07·CVSS 6.8
CVE-2012-0815 [MEDIUM] CVE-2012-0815 rpm: incorrect handling of negated offsets in headerVerifyInfo()
CVE-2012-0815 rpm: incorrect handling of negated offsets in headerVerifyInfo()
A numeric range comparison without minimum check flaw was found within headerVerifyInfo function of RPM library. This function is used by rpm utility to verify the values of header structures (i.e. signature and header sections) of a RPM file. An attacker could create a specially-crafted RPM file that, when read, could cause RPM to crash or, potentially, execute arbitrary code.
Discussion:
Created attachment 566526
RPM 4.8.x patch
---
Created attachment 566527
RPM 4.4.x patch
---
Lifting embargo. Committed upstream now in:
http://rpm.org/gitweb?p=rpm.git;a=commitdiff;h=6fc6b45bf9fef0f17a2900c6c5198bda5e50d09e
---
Created rpm tracking bugs for this issue
Affects: fedora-all [bug 809487]
---
Fixes inc
http://lists.fedoraproject.org/pipermail/package-announce/2012-April/077960.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-April/078819.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-April/078907.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0451.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0531.htmlhttp://rpm.org/gitweb?p=rpm.git%3Ba=commitdiff%3Bh=472e569562d4c90d7a298080e0052856aa7fa86bhttp://rpm.org/gitweb?p=rpm.git%3Ba=commitdiff%3Bh=858a328cd0f7d4bcd8500c78faaf00e4f8033df6http://rpm.org/wiki/Releases/4.9.1.3http://secunia.com/advisories/48651http://secunia.com/advisories/48716http://secunia.com/advisories/49110http://www.mandriva.com/security/advisories?name=MDVSA-2012:056http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.osvdb.org/81009http://www.securityfocus.com/bid/52865http://www.securitytracker.com/id?1026882http://www.ubuntu.com/usn/USN-1695-1https://bugzilla.redhat.com/show_bug.cgi?id=744104https://exchange.xforce.ibmcloud.com/vulnerabilities/74581https://hermes.opensuse.org/messages/14440932https://hermes.opensuse.org/messages/14441362http://lists.fedoraproject.org/pipermail/package-announce/2012-April/077960.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-April/078819.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-April/078907.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0451.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0531.htmlhttp://rpm.org/gitweb?p=rpm.git%3Ba=commitdiff%3Bh=472e569562d4c90d7a298080e0052856aa7fa86bhttp://rpm.org/gitweb?p=rpm.git%3Ba=commitdiff%3Bh=858a328cd0f7d4bcd8500c78faaf00e4f8033df6http://rpm.org/wiki/Releases/4.9.1.3http://secunia.com/advisories/48651http://secunia.com/advisories/48716http://secunia.com/advisories/49110http://www.mandriva.com/security/advisories?name=MDVSA-2012:056http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.osvdb.org/81009http://www.securityfocus.com/bid/52865http://www.securitytracker.com/id?1026882http://www.ubuntu.com/usn/USN-1695-1https://bugzilla.redhat.com/show_bug.cgi?id=744104https://exchange.xforce.ibmcloud.com/vulnerabilities/74581https://hermes.opensuse.org/messages/14440932https://hermes.opensuse.org/messages/14441362
2012-06-04
Published