cbcvebase.
CVE-2013-6435
published 2014-12-16

CVE-2013-6435: Race condition in RPM 4.11.1 and earlier allows remote attackers to execute arbitrary code via a crafted RPM file whose installation extracts the contents to…

PriorityP349high7.6CVSS 2.0
AVNACHAuNCCICAC
EPSS
7.67%
93.9th percentile
Race condition in RPM 4.11.1 and earlier allows remote attackers to execute arbitrary code via a crafted RPM file whose installation extracts the contents to temporary files before validating the signature, as demonstrated by installing a file in the /etc/cron.d directory.

Affected

109 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianrpm< rpm 4.11.3-1.1 (bookworm)rpm 4.11.3-1.1 (bookworm)
rpmrpm<= 4.11.1
rpmrpm
rpmrpm
rpmrpm
rpmrpm
rpmrpm
rpmrpm
rpmrpm
rpmrpm
rpmrpm
rpmrpm
rpmrpm
rpmrpm
rpmrpm
rpmrpm
rpmrpm
rpmrpm
rpmrpm
rpmrpm
rpmrpm
rpmrpm
rpmrpm
rpmrpm

CVSS provenance

nvdv2.07.6HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
osv7.6HIGH
vendor_debian7.6HIGH
vendor_redhat7.6HIGH
vendor_ubuntu7.6HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.