Bugzilla – Bug 217292
VUL-0: CVE-2006-5466: rpm: heap overflow
Last modified: 2021-09-10 14:14:09 UTC
Here we go. ----- Forwarded message from Josh Bressers <bressers@redhat.com> ----- To: vendor-sec@lst.de From: Josh Bressers <bressers@redhat.com> Subject: [vendor-sec] RPM heap overflow (CVE-2006-5466) Errors-To: vendor-sec-admin@lst.de Date: Tue, 31 Oct 2006 21:35:58 -0500 This bug hit our bugzilla a few days ago. Those of you who ship RPM may care about this. https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=212833 It seems that when certain languages are set (so far only ru_RU.UTF-8 is proven to work), an rpm query can overflow a buffer. -- JB _______________________________________________ Vendor Security mailing list Vendor Security@lst.de https://www.lst.de/cgi-bin/mailman/listinfo/vendor-sec
Fixed in STABLE.
CVE-2006-5466: CVSS v2 Base Score: 5.4 (AV:N/AC:H/Au:N/C:N/I:N/A:C)