CVE-2014-8118

Public on 2014-12-09
Modified on 2014-12-10
Description
Integer overflow in RPM 4.12 and earlier allows remote attackers to execute arbitrary code via a crafted CPIO header in the payload section of an RPM file, which triggers a stack-based buffer overflow.
Severity
Important severity
Important
CVSS v3 Base Score
7.6
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 1 rpm 2014-12-09 ALAS-2014-458 Fixed

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv2 7.6 AV:N/AC:H/Au:N/C:C/I:C/A:C
NVD CVSSv2 10.0 AV:N/AC:L/Au:N/C:C/I:C/A:C