5.4
CVSSv2

CVE-2006-5466

Published: 06/11/2006 Updated: 08/03/2011
CVSS v2 Base Score: 5.4 | Impact Score: 6.9 | Exploitability Score: 4.9
VMScore: 481
Vector: AV:N/AC:H/Au:N/C:N/I:N/A:C

Vulnerability Summary

Heap-based buffer overflow in the showQueryPackage function in librpm in RPM Package Manager 4.4.8, when the LANG environment variable is set to ru_RU.UTF-8, might allow user-assisted malicious users to execute arbitrary code via crafted RPM packages.

Vulnerable Product Search on Vulmon Subscribe to Product

rpm package manager 4.4.8

ubuntu ubuntu linux 6.06_lts

ubuntu ubuntu linux 6.10

Vendor Advisories

Debian Bug report logs - #397076 rpm: CVE-2006-5466 Package: rpm; Maintainer for rpm is RPM packaging team <team+pkg-rpm@trackerdebianorg>; Source for rpm is src:rpm (PTS, buildd, popcon) Reported by: Adrian Bunk <bunk@stustade> Date: Sun, 5 Nov 2006 00:18:13 UTC Severity: grave Tags: security Found in version ...
An error was found in the RPM library’s handling of query reports In some locales, certain RPM packages would cause the library to crash If a user was tricked into querying a specially crafted RPM package, the flaw could be exploited to execute arbitrary code with the user’s privileges ...