First published: Mon Oct 03 2011(Updated: )
The RPM Package Manager (RPM) is a command line driven package management<br>system capable of installing, uninstalling, verifying, querying, and<br>updating software packages.<br>Multiple flaws were found in the way the RPM library parsed package<br>headers. An attacker could create a specially-crafted RPM package that,<br>when queried or installed, would cause rpm to crash or, potentially,<br>execute arbitrary code. (CVE-2011-3378)<br>Note: Although an RPM package can, by design, execute arbitrary code when<br>installed, this issue would allow a specially-crafted RPM package to<br>execute arbitrary code before its digital signature has been verified.<br>Package downloads from the Red Hat Network remain secure due to certificate<br>checks performed on the secure connection.<br>All RPM users should upgrade to these updated packages, which contain a<br>backported patch to correct these issues. All running applications linked<br>against the RPM library must be restarted for this update to take effect.<br>
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/rpm | <4.8.0-16.el6_1.1 | 4.8.0-16.el6_1.1 |
redhat/rpm | <4.8.0-16.el6_1.1 | 4.8.0-16.el6_1.1 |
redhat/rpm-apidocs | <4.8.0-16.el6_1.1 | 4.8.0-16.el6_1.1 |
redhat/rpm-build | <4.8.0-16.el6_1.1 | 4.8.0-16.el6_1.1 |
redhat/rpm-cron | <4.8.0-16.el6_1.1 | 4.8.0-16.el6_1.1 |
redhat/rpm-debuginfo | <4.8.0-16.el6_1.1 | 4.8.0-16.el6_1.1 |
redhat/rpm-debuginfo | <4.8.0-16.el6_1.1 | 4.8.0-16.el6_1.1 |
redhat/rpm-devel | <4.8.0-16.el6_1.1 | 4.8.0-16.el6_1.1 |
redhat/rpm-devel | <4.8.0-16.el6_1.1 | 4.8.0-16.el6_1.1 |
redhat/rpm-libs | <4.8.0-16.el6_1.1 | 4.8.0-16.el6_1.1 |
redhat/rpm-libs | <4.8.0-16.el6_1.1 | 4.8.0-16.el6_1.1 |
redhat/rpm-python | <4.8.0-16.el6_1.1 | 4.8.0-16.el6_1.1 |
redhat/rpm-build | <4.8.0-16.el6_1.1 | 4.8.0-16.el6_1.1 |
redhat/rpm-python | <4.8.0-16.el6_1.1 | 4.8.0-16.el6_1.1 |
redhat/rpm | <4.4.2.3-22.el5_7.2 | 4.4.2.3-22.el5_7.2 |
redhat/popt | <1.10.2.3-22.el5_7.2 | 1.10.2.3-22.el5_7.2 |
redhat/popt | <1.10.2.3-22.el5_7.2 | 1.10.2.3-22.el5_7.2 |
redhat/rpm | <4.4.2.3-22.el5_7.2 | 4.4.2.3-22.el5_7.2 |
redhat/rpm-apidocs | <4.4.2.3-22.el5_7.2 | 4.4.2.3-22.el5_7.2 |
redhat/rpm-build | <4.4.2.3-22.el5_7.2 | 4.4.2.3-22.el5_7.2 |
redhat/rpm-devel | <4.4.2.3-22.el5_7.2 | 4.4.2.3-22.el5_7.2 |
redhat/rpm-devel | <4.4.2.3-22.el5_7.2 | 4.4.2.3-22.el5_7.2 |
redhat/rpm-libs | <4.4.2.3-22.el5_7.2 | 4.4.2.3-22.el5_7.2 |
redhat/rpm-libs | <4.4.2.3-22.el5_7.2 | 4.4.2.3-22.el5_7.2 |
redhat/rpm-python | <4.4.2.3-22.el5_7.2 | 4.4.2.3-22.el5_7.2 |
redhat/rpm-apidocs | <4.4.2.3-22.el5_7.2 | 4.4.2.3-22.el5_7.2 |
redhat/rpm-build | <4.4.2.3-22.el5_7.2 | 4.4.2.3-22.el5_7.2 |
redhat/rpm-python | <4.4.2.3-22.el5_7.2 | 4.4.2.3-22.el5_7.2 |
redhat/rpm | <4.3.3-35_nonptl.el4 | 4.3.3-35_nonptl.el4 |
redhat/popt | <1.9.1-35_nonptl.el4 | 1.9.1-35_nonptl.el4 |
redhat/popt | <1.9.1-35_nonptl.el4 | 1.9.1-35_nonptl.el4 |
redhat/rpm | <4.3.3-35_nonptl.el4 | 4.3.3-35_nonptl.el4 |
redhat/rpm-build | <4.3.3-35_nonptl.el4 | 4.3.3-35_nonptl.el4 |
redhat/rpm-devel | <4.3.3-35_nonptl.el4 | 4.3.3-35_nonptl.el4 |
redhat/rpm-libs | <4.3.3-35_nonptl.el4 | 4.3.3-35_nonptl.el4 |
redhat/rpm-libs | <4.3.3-35_nonptl.el4 | 4.3.3-35_nonptl.el4 |
redhat/rpm-python | <4.3.3-35_nonptl.el4 | 4.3.3-35_nonptl.el4 |
redhat/rpm-build | <4.3.3-35_nonptl.el4 | 4.3.3-35_nonptl.el4 |
redhat/rpm-devel | <4.3.3-35_nonptl.el4 | 4.3.3-35_nonptl.el4 |
redhat/rpm-python | <4.3.3-35_nonptl.el4 | 4.3.3-35_nonptl.el4 |
redhat/rpm | <4.4.2.3-22.el5_6.2 | 4.4.2.3-22.el5_6.2 |
redhat/popt | <1.10.2.3-22.el5_6.2 | 1.10.2.3-22.el5_6.2 |
redhat/popt | <1.10.2.3-22.el5_6.2 | 1.10.2.3-22.el5_6.2 |
redhat/rpm | <4.4.2.3-22.el5_6.2 | 4.4.2.3-22.el5_6.2 |
redhat/rpm-apidocs | <4.4.2.3-22.el5_6.2 | 4.4.2.3-22.el5_6.2 |
redhat/rpm-build | <4.4.2.3-22.el5_6.2 | 4.4.2.3-22.el5_6.2 |
redhat/rpm-devel | <4.4.2.3-22.el5_6.2 | 4.4.2.3-22.el5_6.2 |
redhat/rpm-devel | <4.4.2.3-22.el5_6.2 | 4.4.2.3-22.el5_6.2 |
redhat/rpm-libs | <4.4.2.3-22.el5_6.2 | 4.4.2.3-22.el5_6.2 |
redhat/rpm-libs | <4.4.2.3-22.el5_6.2 | 4.4.2.3-22.el5_6.2 |
redhat/rpm-python | <4.4.2.3-22.el5_6.2 | 4.4.2.3-22.el5_6.2 |
redhat/rpm-apidocs | <4.4.2.3-22.el5_6.2 | 4.4.2.3-22.el5_6.2 |
redhat/rpm-build | <4.4.2.3-22.el5_6.2 | 4.4.2.3-22.el5_6.2 |
redhat/rpm-python | <4.4.2.3-22.el5_6.2 | 4.4.2.3-22.el5_6.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.