Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:24728
HistoryApr 10, 2020 - 1:03 a.m.

Arbitrary Code Execution

2020-04-1001:03:00
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7

0.061 Low

EPSS

Percentile

93.6%

rpm is vulnerable to arbitrary code execution. The vulnerability exists as multiple flaws were found in the way the RPM library parsed package headers. An attacker could create a specially-crafted RPM package that, when queried or installed, would cause rpm to crash or, potentially, execute arbitrary code.

References