MEDIUM
RPM Crash after listing contents of non-installed package
Published Nov 6, 2006
5.4
MEDIUMCVSS 2.0
EPSS 3.87%
Description
Heap-based buffer overflow in the showQueryPackage function in librpm in RPM Package Manager 4.4.8, when the LANG environment variable is set to ru_RU.UTF-8, might allow user-assisted attackers to execute arbitrary code via crafted RPM packages.
Affected products
No data.
Configuration 1
- 4.4.8
Configuration 2
OR
- 6.06_lts
- 6.10
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat non longer plans to fix this flaw in Red Hat Enterprise Linux 4.
Weaknesses (0)
No CWE recorded.
References (16)
- http://secunia.com/advisories/22740 third-party-advisoryx_refsource_SECUNIAExploitVendor Advisory
- http://secunia.com/advisories/22745 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/22768 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/22854 third-party-advisoryx_refsource_SECUNIA
- http://security.gentoo.org/glsa/glsa-200611-08.xml vendor-advisoryx_refsource_GENTOO
- http://securitytracker.com/id?1017160 vdb-entryx_refsource_SECTRACK
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:200 vendor-advisoryx_refsource_MANDRIVA
- http://www.securityfocus.com/bid/20906 vdb-entryx_refsource_BID
- http://www.ubuntu.com/usn/usn-378-1 vendor-advisoryx_refsource_UBUNTUPatch
- http://www.vupen.com/english/advisories/2006/4350 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2006-5466 Vendor Advisory
- https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=212833 x_refsource_MISCExploit
- https://bugzilla.redhat.com/show_bug.cgi?id=213515 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2006-5451 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2006-5466
- https://www.cve.org/CVERecord?id=CVE-2006-5466
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Nov 6, 2006
Updated Aug 7, 2024
Reserved Oct 23, 2006
Link CVE-2006-5466
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2006-5451 Assigner redhat
Published Nov 6, 2006
Updated Aug 7, 2024
Exploited since n/a
Link EUVD-2006-5451