|
|
| |
|
| |
rpm: code execution
| Package(s): | rpm |
CVE #(s): | CVE-2012-0060
CVE-2012-0061
CVE-2012-0815
|
| Created: | April 4, 2012 |
Updated: | May 7, 2012 |
| Description: |
The rpm utility has several parsing flaws that can be exploited via a malicious package file to crash the tool or execute arbitrary code. Importantly, the exploit can happen before the validation of the package file's digital signature, so the checks that would normally stop a hostile package file are ineffective here. |
| Alerts: |
|
( Log in to post comments)
|
|
|