CVE-2013-1910
published 2019-10-31CVE-2013-1910: yum does not properly handle bad metadata, which allows an attacker to cause a denial of service and possibly have other unspecified impact via a Trojan horse…
PriorityP340critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
2.50%
83.1th percentile
yum does not properly handle bad metadata, which allows an attacker to cause a denial of service and possibly have other unspecified impact via a Trojan horse file in the metadata of a remote repository.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| baseurl | yum | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| yum | yum | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
yum: Not removing bad metadata and using it in next run
vendor_redhat·2013-03-27·CVSS 9.8
CVE-2013-1910 [CRITICAL] CWE-347 yum: Not removing bad metadata and using it in next run
yum: Not removing bad metadata and using it in next run
yum does not properly handle bad metadata, which allows an attacker to cause a denial of service and possibly have other unspecified impact via a Trojan horse file in the metadata of a remote repository.
Statement: Not vulnerable. This issue did not affect the versions of yum as shipped with Red Hat Enterprise Linux 5 and 6, as yum in those products did not (try to) use filelists metadata yet.
Package: yum (Red Hat Enterprise Linux 5) - Not affected
Package: yum (Red Hat Enterprise Linux 6) - Not affected
GHSA
GHSA-c9v4-8m93-h7r2: yum does not properly handle bad metadata, which allows an attacker to cause a denial of service and possibly have other unspecified impact via a Troj
ghsa_unreviewed·2022-05-05
CVE-2013-1910 [CRITICAL] CWE-20 GHSA-c9v4-8m93-h7r2: yum does not properly handle bad metadata, which allows an attacker to cause a denial of service and possibly have other unspecified impact via a Troj
yum does not properly handle bad metadata, which allows an attacker to cause a denial of service and possibly have other unspecified impact via a Trojan horse file in the metadata of a remote repository.
OSV
CVE-2013-1910: yum does not properly handle bad metadata, which allows an attacker to cause a denial of service and possibly have other unspecified impact via a Troj
osv·2019-10-31·CVSS 9.8
CVE-2013-1910 [CRITICAL] CVE-2013-1910: yum does not properly handle bad metadata, which allows an attacker to cause a denial of service and possibly have other unspecified impact via a Troj
yum does not properly handle bad metadata, which allows an attacker to cause a denial of service and possibly have other unspecified impact via a Trojan horse file in the metadata of a remote repository.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2013/03/29/4http://www.securityfocus.com/bid/58533https://access.redhat.com/security/cve/cve-2013-1910https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-1910https://exchange.xforce.ibmcloud.com/vulnerabilities/83348https://security-tracker.debian.org/tracker/CVE-2013-1910http://www.openwall.com/lists/oss-security/2013/03/29/4http://www.securityfocus.com/bid/58533https://access.redhat.com/security/cve/cve-2013-1910https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-1910https://exchange.xforce.ibmcloud.com/vulnerabilities/83348https://security-tracker.debian.org/tracker/CVE-2013-1910
2019-10-31
Published