CVE-2014-8118Integer Overflow or Wraparound in RPM

Severity
10.0CRITICALNVD
OSV7.6
EPSS
11.8%
top 6.26%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 16
Latest updateMay 14

Description

Integer overflow in RPM 4.12 and earlier allows remote attackers to execute arbitrary code via a crafted CPIO header in the payload section of an RPM file, which triggers a stack-based buffer overflow.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages4 packages

debiandebian/rpm< rpm 4.11.3-1.1 (bookworm)
Debianrpm/rpm< 4.11.3-1.1+3
Ubunturpm/rpm< 4.11.1-3ubuntu0.1
NVDrpm/rpm4.12.0+101

🔴Vulnerability Details

3
GHSA
GHSA-wj3v-j872-6xqx: Integer overflow in RPM 42022-05-14
OSV
rpm vulnerabilities2015-01-19
OSV
CVE-2014-8118: Integer overflow in RPM 42014-12-16

💥Exploits & PoCs

1
Exploit-DB
kitForm CRM Extension 0.43 - 'sorter.ph?sorter_value' SQL Injection2014-04-22

📋Vendor Advisories

3
Ubuntu
RPM vulnerabilities2015-01-19
Red Hat
rpm: integer overflow and stack overflow in CPIO header parsing2014-12-09
Debian
CVE-2014-8118: rpm - Integer overflow in RPM 4.12 and earlier allows remote attackers to execute arbi...2014

💬Community

2
Bugzilla
CVE-2014-8118 CVE-2013-6435 rpm: various flaws [fedora-all]2014-12-09
Bugzilla
CVE-2014-8118 rpm: integer overflow and stack overflow in CPIO header parsing2014-11-27
CVE-2014-8118 — Integer Overflow or Wraparound in RPM | cvebase