Oval Definition:oval:com.redhat.rhsa:def:20120451
Revision Date:2012-04-03Version:638
Title:RHSA-2012:0451: rpm security update (Important)
Description:The RPM Package Manager (RPM) is a command-line driven package management system capable of installing, uninstalling, verifying, querying, and updating software packages.

  • Multiple flaws were found in the way RPM parsed package file headers. An attacker could create a specially-crafted RPM package that, when its package header was accessed, or during package signature verification, could cause an application using the RPM library (such as the rpm command line tool, or the yum and up2date package managers) to crash or, potentially, execute arbitrary code. (CVE-2012-0060, CVE-2012-0061, CVE-2012-0815)

    Note: Although an RPM package can, by design, execute arbitrary code when installed, this issue would allow a specially-crafted RPM package to execute arbitrary code before its digital signature has been verified. Package downloads from the Red Hat Network are protected by the use of a secure HTTPS connection in addition to the RPM package signature checks.

    All RPM users should upgrade to these updated packages, which contain a backported patch to correct these issues. All running applications linked against the RPM library must be restarted for this update to take effect.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2012-0060
    CVE-2012-0060
    CVE-2012-0061
    CVE-2012-0061
    CVE-2012-0815
    CVE-2012-0815
    RHSA-2012:0451
    RHSA-2012:0451-03
    RHSA-2012:0451-03
    Platform(s):Red Hat Enterprise Linux 5
    Red Hat Enterprise Linux 6
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 6 is installed
  • AND
  • rpm is earlier than 0:4.8.0-19.el6_2.1
  • AND rpm is signed with Red Hat redhatrelease2 key
  • rpm-apidocs is earlier than 0:4.8.0-19.el6_2.1
  • AND rpm-apidocs is signed with Red Hat redhatrelease2 key
  • rpm-build is earlier than 0:4.8.0-19.el6_2.1
  • AND rpm-build is signed with Red Hat redhatrelease2 key
  • rpm-cron is earlier than 0:4.8.0-19.el6_2.1
  • AND rpm-cron is signed with Red Hat redhatrelease2 key
  • rpm-devel is earlier than 0:4.8.0-19.el6_2.1
  • AND rpm-devel is signed with Red Hat redhatrelease2 key
  • rpm-libs is earlier than 0:4.8.0-19.el6_2.1
  • AND rpm-libs is signed with Red Hat redhatrelease2 key
  • rpm-python is earlier than 0:4.8.0-19.el6_2.1
  • AND rpm-python is signed with Red Hat redhatrelease2 key
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND
  • popt is earlier than 0:1.10.2.3-28.el5_8
  • AND popt is signed with Red Hat redhatrelease2 key
  • rpm is earlier than 0:4.4.2.3-28.el5_8
  • AND rpm is signed with Red Hat redhatrelease2 key
  • rpm-apidocs is earlier than 0:4.4.2.3-28.el5_8
  • AND rpm-apidocs is signed with Red Hat redhatrelease2 key
  • rpm-build is earlier than 0:4.4.2.3-28.el5_8
  • AND rpm-build is signed with Red Hat redhatrelease2 key
  • rpm-devel is earlier than 0:4.4.2.3-28.el5_8
  • AND rpm-devel is signed with Red Hat redhatrelease2 key
  • rpm-libs is earlier than 0:4.4.2.3-28.el5_8
  • AND rpm-libs is signed with Red Hat redhatrelease2 key
  • rpm-python is earlier than 0:4.4.2.3-28.el5_8
  • AND rpm-python is signed with Red Hat redhatrelease2 key
  • BACK