First published: Mon Nov 06 2006(Updated: )
Heap-based buffer overflow in the showQueryPackage function in librpm in RPM Package Manager 4.4.8, when the LANG environment variable is set to ru_RU.UTF-8, might allow user-assisted attackers to execute arbitrary code via crafted RPM packages.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Package Manager | =4.4.8 | |
Ubuntu | =6.06_lts | |
Ubuntu | =6.10 | |
=4.4.8 | ||
=6.06_lts | ||
=6.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-5466 is considered a high severity vulnerability due to its potential to execute arbitrary code.
To fix CVE-2006-5466, update the RPM Package Manager to a version that has addressed this vulnerability.
CVE-2006-5466 specifically affects RPM Package Manager version 4.4.8.
CVE-2006-5466 impacts Ubuntu versions 6.06 LTS and 6.10.
CVE-2006-5466 is a heap-based buffer overflow vulnerability.