CVE-2012-0815: Medium severity runit vulnerability
The headerVerifyInfo function in lib/header.c in RPM before 4.9.1.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a negative value in a region offset of a package header, which is not properly handled in a numeric range comparison.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0815?
CVE-2012-0815 has been classified as a security vulnerability that can lead to denial of service and potential arbitrary code execution.
How do I fix CVE-2012-0815?
To fix CVE-2012-0815, upgrade RPM to version 4.9.1.3 or later.
Which versions of RPM are affected by CVE-2012-0815?
CVE-2012-0815 affects versions of RPM prior to 4.9.1.3.
Can CVE-2012-0815 be exploited remotely?
Yes, CVE-2012-0815 can be exploited remotely to cause a denial of service or potentially execute arbitrary code.
What is the impact of exploiting CVE-2012-0815?
Exploiting CVE-2012-0815 can result in a crash of the RPM application and potential unauthorized code execution.