SCIENTIFIC-LINUX-ERRATA Archives

December 2014

SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Pat Riehecky <[log in to unmask]>
Reply To:
Date:
Wed, 10 Dec 2014 15:59:56 +0000
Content-Type:
text/plain
Parts/Attachments:
text/plain (45 lines)
Synopsis:          Important: rpm security update
Advisory ID:       SLSA-2014:1976-1
Issue Date:        2014-12-09
CVE Numbers:       CVE-2013-6435
                   CVE-2014-8118
--

It was found that RPM wrote file contents to the target installation
directory under a temporary name, and verified its cryptographic signature
only after the temporary file has been written completely. Under certain
conditions, the system interprets the unverified temporary file contents
and extracts commands from it. This could allow an attacker to modify
signed RPM files in such a way that they would execute code chosen by the
attacker during package installation. (CVE-2013-6435)

It was found that RPM could encounter an integer overflow, leading to a
stack-based buffer overflow, while parsing a crafted CPIO header in the
payload section of an RPM file. This could allow an attacker to modify
signed RPM files in such a way that they would execute code chosen by the
attacker during package installation. (CVE-2014-8118)

All running applications linked against the RPM library must be restarted
for this update to take effect.
--

SL7
  x86_64
    rpm-4.11.1-18.el7_0.x86_64.rpm
    rpm-build-4.11.1-18.el7_0.x86_64.rpm
    rpm-build-libs-4.11.1-18.el7_0.i686.rpm
    rpm-build-libs-4.11.1-18.el7_0.x86_64.rpm
    rpm-debuginfo-4.11.1-18.el7_0.i686.rpm
    rpm-debuginfo-4.11.1-18.el7_0.x86_64.rpm
    rpm-libs-4.11.1-18.el7_0.i686.rpm
    rpm-libs-4.11.1-18.el7_0.x86_64.rpm
    rpm-python-4.11.1-18.el7_0.x86_64.rpm
    rpm-devel-4.11.1-18.el7_0.i686.rpm
    rpm-devel-4.11.1-18.el7_0.x86_64.rpm
    rpm-sign-4.11.1-18.el7_0.x86_64.rpm
  noarch
    rpm-apidocs-4.11.1-18.el7_0.noarch.rpm
    rpm-cron-4.11.1-18.el7_0.noarch.rpm

- Scientific Linux Development Team

ATOM RSS1 RSS2