CVE-2012-6088

Publication date 31 December 2012

Last updated 24 July 2024


Ubuntu priority

The rpmpkgRead function in lib/package.c in RPM 4.10.x before 4.10.2 does not return an error code in certain situations involving an "unparseable signature," which allows remote attackers to bypass RPM signature checks via a crafted package.

Read the notes from the security team

Status

Package Ubuntu Release Status
rpm 12.10 quantal
Fixed 4.10.0-4ubuntu0.1
12.04 LTS precise
Not affected
11.10 oneiric
Not affected
10.04 LTS lucid
Not affected
8.04 LTS hardy Ignored end of life

Notes


mdeslaur

only affects rpm >= 4.10.0

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
rpm