Vulnerability Details CVE-2012-0060
RPM before 4.9.1.3 does not properly validate region tags, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an invalid region tag in a package header to the (1) headerLoad, (2) rpmReadSignature, or (3) headerVerify function.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.065
EPSS Ranking 90.6%
CVSS Severity
CVSS v2 Score 6.8
Products affected by CVE-2012-0060
-
-
-
-
-
-
-
cpe:2.3:a:rpm:rpm:1.4.2/a
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
cpe:2.3:a:rpm:rpm:2.2.3.10
-
cpe:2.3:a:rpm:rpm:2.2.3.11
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
cpe:2.3:a:rpm:rpm:4.4.2.1
-
cpe:2.3:a:rpm:rpm:4.4.2.2
-
cpe:2.3:a:rpm:rpm:4.4.2.3
-
-
-
-
-
-
-
-
-
-
-
cpe:2.3:a:rpm:rpm:4.9.1.1
-
cpe:2.3:a:rpm:rpm:4.9.1.2