PT-2013-1881 · Rpm · Rpm

Jan Lieskovsky

·

Published

2013-01-18

·

Updated

2023-02-13

·

CVE-2012-6088

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions RPM versions 4.10.x through 4.10.1
Description The issue concerns the rpmpkgRead function in lib/package.c, which fails to return an error code when encountering an "unparseable signature" in certain situations. This allows remote attackers to bypass RPM signature checks by crafting a malicious package.
Recommendations For RPM versions 4.10.x through 4.10.1, update to version 4.10.2 or later to resolve the issue.

Fix

Weakness Enumeration

Related Identifiers

CVE-2012-6088

Affected Products

Rpm