4.3
CVSSv2

CVE-2012-6088

Published: 18/01/2013 Updated: 13/02/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

The rpmpkgRead function in lib/package.c in RPM 4.10.x prior to 4.10.2 does not return an error code in certain situations involving an "unparseable signature," which allows remote malicious users to bypass RPM signature checks via a crafted package.

Vulnerable Product Search on Vulmon Subscribe to Product

rpm rpm 4.10.0

rpm rpm 4.10.1

Vendor Advisories

Debian Bug report logs - #697375 rpm: CVE-2012-6088 Package: rpm; Maintainer for rpm is RPM packaging team <team+pkg-rpm@trackerdebianorg>; Source for rpm is src:rpm (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Fri, 4 Jan 2013 15:00:02 UTC Severity: grave Tags: patch, security Fou ...
RPM could incorrectly validate package signatures ...
DescriptionThe MITRE CVE dictionary describes this issue as: The rpmpkgRead function in lib/packagec in RPM 410x before 4102 does not return an error code in certain situations involving an "unparseable signature," which allows remote attackers to bypass RPM signature checks via a crafted package ...