Vulnerability Details CVE-2013-6435
Race condition in RPM 4.11.1 and earlier allows remote attackers to execute arbitrary code via a crafted RPM file whose installation extracts the contents to temporary files before validating the signature, as demonstrated by installing a file in the /etc/cron.d directory.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.067
EPSS Ranking 90.8%
CVSS Severity
CVSS v2 Score 7.6
Products affected by CVE-2013-6435
-
-
-
-
-
-
-
cpe:2.3:a:rpm:rpm:1.4.2/a
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
cpe:2.3:a:rpm:rpm:2.2.3.10
-
cpe:2.3:a:rpm:rpm:2.2.3.11
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
cpe:2.3:a:rpm:rpm:4.10.3.1
-
-
cpe:2.3:a:rpm:rpm:4.11.0.1
-
-
-
-
-
-
cpe:2.3:a:rpm:rpm:4.4.2.1
-
cpe:2.3:a:rpm:rpm:4.4.2.2
-
cpe:2.3:a:rpm:rpm:4.4.2.3
-
-
-
-
-
-
-
-
-
-
-
cpe:2.3:a:rpm:rpm:4.9.1.1
-
cpe:2.3:a:rpm:rpm:4.9.1.2
-
cpe:2.3:a:rpm:rpm:4.9.1.3
-
cpe:2.3:o:debian:debian_linux:7.0