CVE-2012-0060: Input Validation
RPM before 4.9.1.3 does not properly validate region tags, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an invalid region tag in a package header to the (1) headerLoad, (2) rpmReadSignature, or (3) headerVerify function.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0060?
CVE-2012-0060 is classified as a medium severity vulnerability that can cause denial of service and potentially allow remote code execution.
How do I fix CVE-2012-0060?
To fix CVE-2012-0060, update RPM to version 4.9.1.3 or later, which contains the necessary patches.
Which versions of RPM are affected by CVE-2012-0060?
CVE-2012-0060 affects RPM versions prior to 4.9.1.3, including versions 4.9.1.2 and earlier.
What are the potential impacts of CVE-2012-0060 on my system?
Exploitation of CVE-2012-0060 could lead to a denial of service, causing the system to crash, and may also allow attackers to execute arbitrary code.
Is there a workaround for CVE-2012-0060 before applying the fix?
There are no known effective workarounds for CVE-2012-0060, so applying the update to RPM is the recommended course of action.