Vulnerability Details CVE-2014-8118
Integer overflow in RPM 4.12 and earlier allows remote attackers to execute arbitrary code via a crafted CPIO header in the payload section of an RPM file, which triggers a stack-based buffer overflow.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.118
EPSS Ranking 93.4%
CVSS Severity
CVSS v2 Score 10.0
Products affected by CVE-2014-8118
-
-
-
-
-
-
-
cpe:2.3:a:rpm:rpm:1.4.2/a
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
cpe:2.3:a:rpm:rpm:2.2.3.10
-
cpe:2.3:a:rpm:rpm:2.2.3.11
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
cpe:2.3:a:rpm:rpm:4.10.3.1
-
-
cpe:2.3:a:rpm:rpm:4.11.0.1
-
-
-
-
-
-
-
-
-
cpe:2.3:a:rpm:rpm:4.4.2.1
-
cpe:2.3:a:rpm:rpm:4.4.2.2
-
cpe:2.3:a:rpm:rpm:4.4.2.3
-
-
-
-
-
-
-
-
-
-
-
cpe:2.3:a:rpm:rpm:4.9.1.1
-
cpe:2.3:a:rpm:rpm:4.9.1.2
-
cpe:2.3:a:rpm:rpm:4.9.1.3