Oval Definition:oval:org.mitre.oval:def:28661
Revision Date:2015-02-23Version:9
Title:RHSA-2014:1974 -- rpm security update (Important)
Description:The RPM Package Manager (RPM) is a powerful command line driven packagemanagement system capable of installing, uninstalling, verifying, querying,and updating software packages. Each software package consists of anarchive of files along with information about the package such as itsversion, description, and other information.It was found that RPM wrote file contents to the target installationdirectory under a temporary name, and verified its cryptographic signatureonly after the temporary file has been written completely. Under certainconditions, the system interprets the unverified temporary file contentsand extracts commands from it. This could allow an attacker to modifysigned RPM files in such a way that they would execute code chosen by theattacker during package installation. (CVE-2013-6435)This issue was discovered by Florian Weimer of Red Hat Product Security.All rpm users are advised to upgrade to these updated packages, whichcontain a backported patch to correct this issue. All running applicationslinked against the RPM library must be restarted for this update to takeeffect.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CESA-2014:1974-CentOS 5
CESA-2014:1974-CentOS 6
CVE-2013-6435
RHSA-2014:1974
Platform(s):CentOS Linux 5
CentOS Linux 6
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 6
Product(s):rpm
Definition Synopsis
  • Red Hat Enterprise Linux 5 and CentOS Linux 5 release section
  • Operation system section
  • The operating system installed on the system is Red Hat Enterprise Linux 5
  • OR The operating system installed on the system is CentOS Linux 5.x
  • AND Packages match section
  • rpm-apidocs is earlier than 0:4.4.2.3-36.el5_11
  • OR rpm-build is earlier than 0:4.4.2.3-36.el5_11
  • OR rpm-devel is earlier than 0:4.4.2.3-36.el5_11
  • OR popt is earlier than 0:1.10.2.3-36.el5_11
  • OR rpm is earlier than 0:4.4.2.3-36.el5_11
  • OR rpm-libs is earlier than 0:4.4.2.3-36.el5_11
  • OR rpm-python is earlier than 0:4.4.2.3-36.el5_11
  • Red Hat Enterprise Linux 5 release section
  • The operating system installed on the system is Red Hat Enterprise Linux 5
  • AND rpm-debuginfo is earlier than 0:4.4.2.3-36.el5_11
  • Red Hat Enterprise Linux 6 and CentOS Linux 6 release section
  • Operation system section
  • The operating system installed on the system is Red Hat Enterprise Linux 6
  • OR The operating system installed on the system is CentOS Linux 6.x
  • AND Packages match section
  • rpm is earlier than 0:4.8.0-38.el6_6
  • OR rpm-apidocs is earlier than 0:4.8.0-38.el6_6
  • OR rpm-build is earlier than 0:4.8.0-38.el6_6
  • OR rpm-cron is earlier than 0:4.8.0-38.el6_6
  • OR rpm-devel is earlier than 0:4.8.0-38.el6_6
  • OR rpm-libs is earlier than 0:4.8.0-38.el6_6
  • OR rpm-python is earlier than 0:4.8.0-38.el6_6
  • Red Hat Enterprise Linux 6 release section
  • The operating system installed on the system is Red Hat Enterprise Linux 6
  • AND rpm-debuginfo is earlier than 0:4.8.0-38.el6_6
  • BACK