CVE-2013-6435

Publication date 16 December 2014

Last updated 24 July 2024


Ubuntu priority

Race condition in RPM 4.11.1 and earlier allows remote attackers to execute arbitrary code via a crafted RPM file whose installation extracts the contents to temporary files before validating the signature, as demonstrated by installing a file in the /etc/cron.d directory.

Status

Package Ubuntu Release Status
rpm 14.10 utopic
Fixed 4.11.2-3ubuntu0.1
14.04 LTS trusty
Fixed 4.11.1-3ubuntu0.1
12.04 LTS precise
Fixed 4.9.1.1-1ubuntu0.3
10.04 LTS lucid Ignored end of life

References

Related Ubuntu Security Notices (USN)

Other references