cbcvebase.
CVE-2012-6088
published 2013-01-18

CVE-2012-6088: The rpmpkgRead function in lib/package.c in RPM 4.10.x before 4.10.2 does not return an error code in certain situations involving an "unparseable signature,"…

PriorityP423medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
2.25%
81.0th percentile
The rpmpkgRead function in lib/package.c in RPM 4.10.x before 4.10.2 does not return an error code in certain situations involving an "unparseable signature," which allows remote attackers to bypass RPM signature checks via a crafted package.

Affected

7 ranges
VendorProductVersion rangeFixed in
debianrpm< rpm 4.10.1-2.1 (bookworm)rpm 4.10.1-2.1 (bookworm)
rpmrpm
rpmrpm
rpmrpm>= 0 < 4.10.1-2.14.10.1-2.1
rpmrpm>= 0 < 4.10.1-2.14.10.1-2.1
rpmrpm>= 0 < 4.10.1-2.14.10.1-2.1
rpmrpm>= 0 < 4.10.1-2.14.10.1-2.1

CVSS provenance

nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.