← Back

CVE-2013-6435

nvd nist
Published: Dec 16, 2014Modified: May 6, 2026

JSON object

Loading...
7.6
Vector
AV:N/AC:H/Au:N/C:C/I:C/A:C
Exploitability: 4.9 / Impact: 10.0
Source: NVD

Description

Race condition in RPM 4.11.1 and earlier allows remote attackers to execute arbitrary code via a crafted RPM file whose installation extracts the contents to temporary files before validating the signature, as demonstrated by installing a file in the /etc/cron.d directory.

Affected (110)

Products: Rpm: Rpm · Debian: Debian Linux
1 product
Rpm
1 product
Debian Linux
Configuration A
109 vulnerable
Vulnerable SoftwareAffected Versions
Rpm
Up to 4.11.1
Version 1.2
Version 1.3.1
Version 1.3
Version 1.4.1
Version 1.4.2
Version 1.4.2/a
Version 1.4.3
Version 1.4.4
Version 1.4.5
Version 1.4.6
Version 1.4.7
Version 1.4
Version 2.0.10
Version 2.0.11
Version 2.0.1
Version 2.0.2
Version 2.0.3
Version 2.0.4
Version 2.0.5
Version 2.0.6
Version 2.0.7
Version 2.0.8
Version 2.0.9
Version 2.0
Version 2.1.1
Version 2.1.2
Version 2.1
Version 2.2.10
Version 2.2.11
Version 2.2.1
Version 2.2.2
Version 2.2.3.10
Version 2.2.3.11
Version 2.2.3
Version 2.2.4
Version 2.2.5
Version 2.2.6
Version 2.2.7
Version 2.2.8
Version 2.2.9
Version 2.2
Version 2.3.1
Version 2.3.2
Version 2.3.3
Version 2.3.4
Version 2.3.5
Version 2.3.6
Version 2.3.7
Version 2.3.8
Version 2.3.9
Version 2.3
Version 2.4.11
Version 2.4.12
Version 2.4.1
Version 2.4.2
Version 2.4.3
Version 2.4.4
Version 2.4.5
Version 2.4.6
Version 2.4.8
Version 2.4.9
Version 2.5.1
Version 2.5.2
Version 2.5.3
Version 2.5.4
Version 2.5.5
Version 2.5.6
Version 2.5
Version 2.6.7
Version 3.0.1
Version 3.0.2
Version 3.0.3
Version 3.0.4
Version 3.0.5
Version 3.0.6
Version 3.0
Version 4.0.1
Version 4.0.2
Version 4.0.3
Version 4.0.4
Version 4.0.
Version 4.10.0
Version 4.10.1
Version 4.10.2
Version 4.1
Version 4.3.3
Version 4.4.2.1
Version 4.4.2.2
Version 4.4.2.3
Version 4.5.90
Version 4.6.0
Version 4.6.0 rc1
Version 4.6.0 rc2
Version 4.6.0 rc3
Version 4.6.0 rc4
Version 4.6.1
Version 4.7.0
Version 4.7.1
Version 4.7.2
Version 4.8.0
Version 4.8.1
Version 4.9.0
Version 4.9.0 alpha
Version 4.9.0 beta1
Version 4.9.0 rc1
Version 4.9.1.1
Version 4.9.1.2
Version 4.9.1
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 7.0

References (26)

Source: secalert@redhat.com
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.