CVE-2011-3378
rpm: crashes and overflows on malformed header
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
RPM 4.4.x through 4.9.x, probably before 4.9.1.2, allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via an rpm package with crafted headers and offsets that are not properly handled when a package is queried or installed, related to (1) the regionSwab function, (2) the headerLoad function, and (3) multiple functions in rpmio/rpmpgp.c.
RPM v4.4.x hasta v4.9.x, probablemente antes de v4.9.1.2, permite a atacantes remotos provocar una denegación de servicio (corrupción de memoria) y posiblemente ejecutar código arbitrario a través de un paquete RPM con cabeceras manipuladas y "offsets" que no son manipulados correctamente cuando un paquete es consultado o instalado, relacionado con (1) la función regionSwab, (2) la función headerLoad, y (3) múltiples funciones en rpmio/rpmpgp.c.
The RPM Package Manager is a command line driven package management system capable of installing, uninstalling, verifying, querying, and updating software packages. Multiple flaws were found in the way the RPM library parsed package headers. An attacker could create a specially-crafted RPM package that, when queried or installed, would cause rpm to crash or, potentially, execute arbitrary code. Note: Although an RPM package can, by design, execute arbitrary code when installed, this issue would allow a specially-crafted RPM package to execute arbitrary code before its digital signature has been verified. Package downloads from the Red Hat Network remain secure due to certificate checks performed on the secure connection.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2011-08-30 CVE Reserved
- 2011-10-03 CVE Published
- 2024-08-06 CVE Updated
- 2024-08-06 First Exploit
- 2025-05-15 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-94: Improper Control of Generation of Code ('Code Injection')
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (13)
URL | Tag | Source |
---|---|---|
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10691 | X_refsource_confirm | |
http://rpm.org/gitweb?p=rpm.git%3Ba=commitdiff%3Bh=11a7e5d95a8ca8c7d4eaff179094afd8bb74fc3f | X_refsource_confirm | |
http://rpm.org/gitweb?p=rpm.git%3Ba=commitdiff%3Bh=a48f0e20cbe2ababc88b2fc52fb7a281d6fc1656 | X_refsource_confirm | |
http://www.openwall.com/lists/oss-security/2011/09/27/3 | Mailing List |
|
URL | Date | SRC |
---|---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=741612 | 2024-08-06 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Rpm Search vendor "Rpm" | Rpm Search vendor "Rpm" for product "Rpm" | <= 4.9.1.1 Search vendor "Rpm" for product "Rpm" and version " <= 4.9.1.1" | - |
Affected
| ||||||
Rpm Search vendor "Rpm" | Rpm Search vendor "Rpm" for product "Rpm" | 4.4.2 Search vendor "Rpm" for product "Rpm" and version "4.4.2" | - |
Affected
| ||||||
Rpm Search vendor "Rpm" | Rpm Search vendor "Rpm" for product "Rpm" | 4.4.2. Search vendor "Rpm" for product "Rpm" and version "4.4.2." | - |
Affected
| ||||||
Rpm Search vendor "Rpm" | Rpm Search vendor "Rpm" for product "Rpm" | 4.4.2.1 Search vendor "Rpm" for product "Rpm" and version "4.4.2.1" | - |
Affected
| ||||||
Rpm Search vendor "Rpm" | Rpm Search vendor "Rpm" for product "Rpm" | 4.4.2.2 Search vendor "Rpm" for product "Rpm" and version "4.4.2.2" | - |
Affected
| ||||||
Rpm Search vendor "Rpm" | Rpm Search vendor "Rpm" for product "Rpm" | 4.4.2.3 Search vendor "Rpm" for product "Rpm" and version "4.4.2.3" | - |
Affected
| ||||||
Rpm Search vendor "Rpm" | Rpm Search vendor "Rpm" for product "Rpm" | 4.6.0 Search vendor "Rpm" for product "Rpm" and version "4.6.0" | - |
Affected
| ||||||
Rpm Search vendor "Rpm" | Rpm Search vendor "Rpm" for product "Rpm" | 4.6.1 Search vendor "Rpm" for product "Rpm" and version "4.6.1" | - |
Affected
| ||||||
Rpm Search vendor "Rpm" | Rpm Search vendor "Rpm" for product "Rpm" | 4.7.0 Search vendor "Rpm" for product "Rpm" and version "4.7.0" | - |
Affected
| ||||||
Rpm Search vendor "Rpm" | Rpm Search vendor "Rpm" for product "Rpm" | 4.7.1 Search vendor "Rpm" for product "Rpm" and version "4.7.1" | - |
Affected
| ||||||
Rpm Search vendor "Rpm" | Rpm Search vendor "Rpm" for product "Rpm" | 4.7.2 Search vendor "Rpm" for product "Rpm" and version "4.7.2" | - |
Affected
| ||||||
Rpm Search vendor "Rpm" | Rpm Search vendor "Rpm" for product "Rpm" | 4.8.0 Search vendor "Rpm" for product "Rpm" and version "4.8.0" | - |
Affected
|