// For flags

CVE-2012-0815

rpm: incorrect handling of negated offsets in headerVerifyInfo()

Severity Score

6.8
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The headerVerifyInfo function in lib/header.c in RPM before 4.9.1.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a negative value in a region offset of a package header, which is not properly handled in a numeric range comparison.

La función headerVerifyInfo de lib/header.c de RPM anteriores a 4.9.1.3 permite a atacantes remotos provocar una denegación de servicio (caída) y posiblemente ejecutar código arbitrario a través de un valor negativo en un elemento "region offset" de una cabecera de paquete, que no es manejado apropiadamente en una comparación de rango numérico.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
Attack Vector
Network
Attack Complexity
High
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2012-01-19 CVE Reserved
  • 2012-04-03 CVE Published
  • 2024-04-30 EPSS Updated
  • 2024-08-06 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
  • CWE-189: Numeric Errors
CAPEC
References (22)
URL Date SRC
URL Date SRC
http://rpm.org/wiki/Releases/4.9.1.3 2023-11-07
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
<= 4.9.1.2
Search vendor "Rpm" for product "Rpm" and version " <= 4.9.1.2"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
1.2
Search vendor "Rpm" for product "Rpm" and version "1.2"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
1.3
Search vendor "Rpm" for product "Rpm" and version "1.3"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
1.3.1
Search vendor "Rpm" for product "Rpm" and version "1.3.1"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
1.4
Search vendor "Rpm" for product "Rpm" and version "1.4"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
1.4.1
Search vendor "Rpm" for product "Rpm" and version "1.4.1"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
1.4.2
Search vendor "Rpm" for product "Rpm" and version "1.4.2"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
1.4.2\/a
Search vendor "Rpm" for product "Rpm" and version "1.4.2\/a"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
1.4.3
Search vendor "Rpm" for product "Rpm" and version "1.4.3"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
1.4.4
Search vendor "Rpm" for product "Rpm" and version "1.4.4"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
1.4.5
Search vendor "Rpm" for product "Rpm" and version "1.4.5"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
1.4.6
Search vendor "Rpm" for product "Rpm" and version "1.4.6"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
1.4.7
Search vendor "Rpm" for product "Rpm" and version "1.4.7"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
2.0
Search vendor "Rpm" for product "Rpm" and version "2.0"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
2.0.1
Search vendor "Rpm" for product "Rpm" and version "2.0.1"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
2.0.2
Search vendor "Rpm" for product "Rpm" and version "2.0.2"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
2.0.3
Search vendor "Rpm" for product "Rpm" and version "2.0.3"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
2.0.4
Search vendor "Rpm" for product "Rpm" and version "2.0.4"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
2.0.5
Search vendor "Rpm" for product "Rpm" and version "2.0.5"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
2.0.6
Search vendor "Rpm" for product "Rpm" and version "2.0.6"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
2.0.7
Search vendor "Rpm" for product "Rpm" and version "2.0.7"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
2.0.8
Search vendor "Rpm" for product "Rpm" and version "2.0.8"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
2.0.9
Search vendor "Rpm" for product "Rpm" and version "2.0.9"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
2.0.10
Search vendor "Rpm" for product "Rpm" and version "2.0.10"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
2.0.11
Search vendor "Rpm" for product "Rpm" and version "2.0.11"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
2.1
Search vendor "Rpm" for product "Rpm" and version "2.1"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
2.1.1
Search vendor "Rpm" for product "Rpm" and version "2.1.1"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
2.1.2
Search vendor "Rpm" for product "Rpm" and version "2.1.2"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
2.2
Search vendor "Rpm" for product "Rpm" and version "2.2"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
2.2.1
Search vendor "Rpm" for product "Rpm" and version "2.2.1"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
2.2.2
Search vendor "Rpm" for product "Rpm" and version "2.2.2"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
2.2.3
Search vendor "Rpm" for product "Rpm" and version "2.2.3"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
2.2.3.10
Search vendor "Rpm" for product "Rpm" and version "2.2.3.10"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
2.2.3.11
Search vendor "Rpm" for product "Rpm" and version "2.2.3.11"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
2.2.4
Search vendor "Rpm" for product "Rpm" and version "2.2.4"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
2.2.5
Search vendor "Rpm" for product "Rpm" and version "2.2.5"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
2.2.6
Search vendor "Rpm" for product "Rpm" and version "2.2.6"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
2.2.7
Search vendor "Rpm" for product "Rpm" and version "2.2.7"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
2.2.8
Search vendor "Rpm" for product "Rpm" and version "2.2.8"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
2.2.9
Search vendor "Rpm" for product "Rpm" and version "2.2.9"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
2.2.10
Search vendor "Rpm" for product "Rpm" and version "2.2.10"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
2.2.11
Search vendor "Rpm" for product "Rpm" and version "2.2.11"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
2.3
Search vendor "Rpm" for product "Rpm" and version "2.3"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
2.3.1
Search vendor "Rpm" for product "Rpm" and version "2.3.1"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
2.3.2
Search vendor "Rpm" for product "Rpm" and version "2.3.2"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
2.3.3
Search vendor "Rpm" for product "Rpm" and version "2.3.3"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
2.3.4
Search vendor "Rpm" for product "Rpm" and version "2.3.4"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
2.3.5
Search vendor "Rpm" for product "Rpm" and version "2.3.5"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
2.3.6
Search vendor "Rpm" for product "Rpm" and version "2.3.6"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
2.3.7
Search vendor "Rpm" for product "Rpm" and version "2.3.7"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
2.3.8
Search vendor "Rpm" for product "Rpm" and version "2.3.8"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
2.3.9
Search vendor "Rpm" for product "Rpm" and version "2.3.9"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
2.4.1
Search vendor "Rpm" for product "Rpm" and version "2.4.1"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
2.4.2
Search vendor "Rpm" for product "Rpm" and version "2.4.2"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
2.4.3
Search vendor "Rpm" for product "Rpm" and version "2.4.3"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
2.4.4
Search vendor "Rpm" for product "Rpm" and version "2.4.4"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
2.4.5
Search vendor "Rpm" for product "Rpm" and version "2.4.5"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
2.4.6
Search vendor "Rpm" for product "Rpm" and version "2.4.6"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
2.4.8
Search vendor "Rpm" for product "Rpm" and version "2.4.8"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
2.4.9
Search vendor "Rpm" for product "Rpm" and version "2.4.9"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
2.4.11
Search vendor "Rpm" for product "Rpm" and version "2.4.11"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
2.4.12
Search vendor "Rpm" for product "Rpm" and version "2.4.12"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
2.5
Search vendor "Rpm" for product "Rpm" and version "2.5"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
2.5.1
Search vendor "Rpm" for product "Rpm" and version "2.5.1"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
2.5.2
Search vendor "Rpm" for product "Rpm" and version "2.5.2"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
2.5.3
Search vendor "Rpm" for product "Rpm" and version "2.5.3"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
2.5.4
Search vendor "Rpm" for product "Rpm" and version "2.5.4"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
2.5.5
Search vendor "Rpm" for product "Rpm" and version "2.5.5"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
2.5.6
Search vendor "Rpm" for product "Rpm" and version "2.5.6"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
2.6.7
Search vendor "Rpm" for product "Rpm" and version "2.6.7"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
3.0
Search vendor "Rpm" for product "Rpm" and version "3.0"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
3.0.1
Search vendor "Rpm" for product "Rpm" and version "3.0.1"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
3.0.2
Search vendor "Rpm" for product "Rpm" and version "3.0.2"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
3.0.3
Search vendor "Rpm" for product "Rpm" and version "3.0.3"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
3.0.4
Search vendor "Rpm" for product "Rpm" and version "3.0.4"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
3.0.5
Search vendor "Rpm" for product "Rpm" and version "3.0.5"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
3.0.6
Search vendor "Rpm" for product "Rpm" and version "3.0.6"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
4.0.
Search vendor "Rpm" for product "Rpm" and version "4.0."
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
4.0.1
Search vendor "Rpm" for product "Rpm" and version "4.0.1"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
4.0.2
Search vendor "Rpm" for product "Rpm" and version "4.0.2"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
4.0.3
Search vendor "Rpm" for product "Rpm" and version "4.0.3"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
4.0.4
Search vendor "Rpm" for product "Rpm" and version "4.0.4"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
4.1
Search vendor "Rpm" for product "Rpm" and version "4.1"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
4.3.3
Search vendor "Rpm" for product "Rpm" and version "4.3.3"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
4.4.2.1
Search vendor "Rpm" for product "Rpm" and version "4.4.2.1"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
4.4.2.2
Search vendor "Rpm" for product "Rpm" and version "4.4.2.2"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
4.4.2.3
Search vendor "Rpm" for product "Rpm" and version "4.4.2.3"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
4.5.90
Search vendor "Rpm" for product "Rpm" and version "4.5.90"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
4.6.0
Search vendor "Rpm" for product "Rpm" and version "4.6.0"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
4.6.0
Search vendor "Rpm" for product "Rpm" and version "4.6.0"
rc1
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
4.6.0
Search vendor "Rpm" for product "Rpm" and version "4.6.0"
rc2
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
4.6.0
Search vendor "Rpm" for product "Rpm" and version "4.6.0"
rc3
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
4.6.0
Search vendor "Rpm" for product "Rpm" and version "4.6.0"
rc4
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
4.6.1
Search vendor "Rpm" for product "Rpm" and version "4.6.1"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
4.7.0
Search vendor "Rpm" for product "Rpm" and version "4.7.0"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
4.7.1
Search vendor "Rpm" for product "Rpm" and version "4.7.1"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
4.7.2
Search vendor "Rpm" for product "Rpm" and version "4.7.2"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
4.8.0
Search vendor "Rpm" for product "Rpm" and version "4.8.0"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
4.8.1
Search vendor "Rpm" for product "Rpm" and version "4.8.1"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
4.9.0
Search vendor "Rpm" for product "Rpm" and version "4.9.0"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
4.9.0
Search vendor "Rpm" for product "Rpm" and version "4.9.0"
alpha
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
4.9.0
Search vendor "Rpm" for product "Rpm" and version "4.9.0"
beta1
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
4.9.0
Search vendor "Rpm" for product "Rpm" and version "4.9.0"
rc1
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
4.9.1
Search vendor "Rpm" for product "Rpm" and version "4.9.1"
-
Affected
Rpm
Search vendor "Rpm"
Rpm
Search vendor "Rpm" for product "Rpm"
4.9.1.1
Search vendor "Rpm" for product "Rpm" and version "4.9.1.1"
-
Affected