CVE-2014-8118 — Integer Overflow or Wraparound in RPM
CWE-189CWE-190 — Integer Overflow or WraparoundCWE-121 — Stack-based Buffer Overflow10 documents8 sources
Severity
10.0CRITICALNVD
OSV7.6
EPSS
11.8%
top 6.26%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 16
Latest updateMay 14
Description
Integer overflow in RPM 4.12 and earlier allows remote attackers to execute arbitrary code via a crafted CPIO header in the payload section of an RPM file, which triggers a stack-based buffer overflow.
CVSS vector
AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0