| Severity : |
Medium
|
| Published : |
2012-06-04
|
| Modified : |
2013-05-03
|
| Base Score : |
6.8
|
| Details : |
The headerVerifyInfo function in lib/header.c in RPM before 4.9.1.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a negative value in a region offset of a package header, which is not properly handled in a numeric range comparison.
|
| Product/Version : |
Pro 5.0
CGE 5.x
Mobilinux 5.x
Mobilinux 5.0.24
MVL 5 Atom
Pro 5.0.24
MVL 5 OMAP3
MVL 5 OMAP3530
Carrier Grade CGE 6.0
Pro 4.x
CGE 4.x
Mobilinux 4.x
|
|
CVE Vulnerabilities List CVE-2012