在 rpm 中发现了一个基于堆的缓冲区溢出漏洞。在一个经过恶意构造且未签名的 RPM 软件包的主头文件中,RPMTAG_FILESIGNATURES 字段被声明为错误的头部类型,导致 hex2binv() 函数仅分配了一个字节的缓冲区,随后将攻击者可控的、经过十六进制解码的内容(其长度由攻击者指定)写入该分配区域之外。此漏洞可通过对不可信软件包执行 rpm2cpio、rpm2archive 或 rpm -qlvp 命令触发。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| Red Hat | Red Hat Hardened Images | - |
cpe:/a:redhat:hummingbird:1
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet