Back to Database
Status published
Critical
CVE-2014-8118
Integer overflow in RPM 4.12 and earlier allows remote attackers...
Vulnerability Description
Integer overflow in RPM 4.12 and earlier allows remote attackers to execute arbitrary code via a crafted CPIO header in the payload section of an RPM file, which triggers a stack-based buffer overflow.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2014-8118
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:056
- https://security.gentoo.org/glsa/201811-22
- http://advisories.mageia.org/MGASA-2014-0529.html
- http://www.mandriva.com/security/advisories?name=MDVSA-2014:251
- http://www.debian.org/security/2015/dsa-3129
- http://rhn.redhat.com/errata/RHSA-2014-1976.html
More from rpm
View All →CVE-2013-6435
Race condition in RPM 4.11.1 and earlier allows remote attackers...
High
7.6
CVE-2012-6088
The rpmpkgRead function in lib/package.c in RPM 4.10.x before 4.10.2...
Medium
4.3
CVE-2012-0815
The headerVerifyInfo function in lib/header.c in RPM before 4.9.1.3 allows...
Medium
6.8
CVE-2012-0061
The headerLoad function in lib/header.c in RPM before 4.9.1.3 does...
Medium
6.8
CVE-2012-0060
RPM before 4.9.1.3 does not properly validate region tags, which...
Medium
6.8
Affected Vendor
Affected Software
rpm
Vulnerable Versions:
0, 1.2, 1.3, 1.3.1, 1.4, 1.4.1, 1.4.2, 1.4.2\/a, 1.4.3, 1.4.4, 1.4.5, 1.4.6, 1.4.7, 2.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, 2.0.6, 2.0.7, 2.0.8, 2.0.9, 2.0.10, 2.0.11, 2.1, 2.1.1, 2.1.2, 2.2, 2.2.1, 2.2.2, 2.2.3, 2.2.3.10, 2.2.3.11, 2.2.4, 2.2.5, 2.2.6, 2.2.7, 2.2.8, 2.2.9, 2.2.10, 2.2.11, 2.3, 2.3.1, 2.3.2, 2.3.3, 2.3.4, 2.3.5, 2.3.6, 2.3.7, 2.3.8, 2.3.9, 2.4.1, 2.4.2, 2.4.3, 2.4.4, 2.4.5, 2.4.6, 2.4.8, 2.4.9, 2.4.11, 2.4.12, 2.5, 2.5.1, 2.5.2, 2.5.3, 2.5.4, 2.5.5, 2.5.6, 2.6.7, 3.0, 3.0.1, 3.0.2, 3.0.3, 3.0.4, 3.0.5, 3.0.6, 4.0., 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.1, 4.3.3, 4.4.2.1, 4.4.2.2, 4.4.2.3, 4.5.90, 4.6.0, 4.6.1, 4.7.0, 4.7.1, 4.7.2, 4.8.0, 4.8.1, 4.9.0, 4.9.1, 4.9.1.1, 4.9.1.2, 4.10.0, 4.10.1, 4.10.2
Timeline
Official Publish:
December 16th, 2014
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.