Heap-based buffer overflow in the showQueryPackage function in librpm in RPM Package Manager 4.4.8, when the LANG environment variable is set to ru_RU.UTF-8, might allow user-assisted attackers to execute arbitrary code via crafted RPM packages.
2006-11-06T17:07:00.000
2025-04-09T00:30:58.490
Deferred
CVSSv2: 5.4 (MEDIUM)
AV:N/AC:H/Au:N/C:N/I:N/A:C
4.9
6.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | rpm | package_manager | 4.4.8 | Yes |
Operating System | ubuntu | ubuntu_linux | 6.06_lts | Yes |
Operating System | ubuntu | ubuntu_linux | 6.10 | Yes |