Vulnerability Details CVE-2012-0815
The headerVerifyInfo function in lib/header.c in RPM before 4.9.1.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a negative value in a region offset of a package header, which is not properly handled in a numeric range comparison.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.07
EPSS Ranking 91.0%
CVSS Severity
CVSS v2 Score 6.8
Products affected by CVE-2012-0815
-
-
-
-
-
-
-
cpe:2.3:a:rpm:rpm:1.4.2/a
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
cpe:2.3:a:rpm:rpm:2.2.3.10
-
cpe:2.3:a:rpm:rpm:2.2.3.11
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
cpe:2.3:a:rpm:rpm:4.4.2.1
-
cpe:2.3:a:rpm:rpm:4.4.2.2
-
cpe:2.3:a:rpm:rpm:4.4.2.3
-
-
-
-
-
-
-
-
-
-
-
cpe:2.3:a:rpm:rpm:4.9.1.1
-
cpe:2.3:a:rpm:rpm:4.9.1.2