CVE-2012-0815
The headerVerifyInfo function in lib/header.c in RPM before 4.9.1.3 allows remote attackers to cause a denial of service
The headerVerifyInfo function in lib/header.c in RPM before 4.9.1.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a negative value in a region offset of a package header, which is not properly handled in a numeric range comparison.
MEDIUM · CVSS 6.8
EPSS 0.06991
Monitor
- EPSS percentile: top 8% of all CVEs by exploitation likelihood
Sigma rules0
YARA rules0