Debian Security Advisory

DSA-3129-1 rpm -- security update

Date Reported:
15 Jan 2015
Affected Packages:
rpm
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2013-6435, CVE-2014-8118.
More information:

Two vulnerabilities have been discovered in the RPM package manager.

  • CVE-2013-6435

    Florian Weimer discovered a race condition in package signature validation.

  • CVE-2014-8118

    Florian Weimer discovered an integer overflow in parsing CPIO headers which might result in the execution of arbitrary code.

For the stable distribution (wheezy), these problems have been fixed in version 4.10.0-5+deb7u2.

For the upcoming stable distribution (jessie), these problems have been fixed in version 4.11.3-1.1.

For the unstable distribution (sid), these problems have been fixed in version 4.11.3-1.1.

We recommend that you upgrade your rpm packages.