SciLinux: CVE-2013-6435 Important: rpm SL5.x, SL6.x i386/x86_64
Important: rpm security update
Date: Wed, 10 Dec 2014 16:13:04 +0000 Reply-To: Sender: Security Errata for Scientific LinuxFrom: Pat Riehecky Subject: Security ERRATA Important: rpm on SL5.x, SL6.x i386/x86_64 MIME-Version: 1.0 Synopsis: Important: rpm security update Advisory ID: SLSA-2014:1974-1 Issue Date: 2014-12-09 CVE Numbers: CVE-2013-6435 -- It was found that RPM wrote file contents to the target installation directory under a temporary name, and verified its cryptographic signature only after the temporary file has been written completely. Under certain conditions, the system interprets the unverified temporary file contents and extracts commands from it. This could allow an attacker to modify signed RPM files in such a way that they would execute code chosen by the attacker during package installation. (CVE-2013-6435) All running applications linked against the RPM library must be restarted for this update to take effect. -- SL5 x86_64 popt- popt- rpm- rpm-debuginfo- rpm-debuginfo- rpm-libs- rpm-libs- rpm-python- rpm-apidocs- rpm-build- rpm-devel- rpm-devel- i386 popt- rpm- rpm-debuginfo- rpm-libs- rpm-python- rpm-apidocs- rpm-build- rpm-devel- SL6 x86_64 rpm-4.8.0-38.el6_6.x86_64.rpm rpm-build-4.8.0-38.el6_6.x86_64.rpm rpm-debuginfo-4.8.0-38.el6_6.i686.rpm rpm-debuginfo-4.8.0-38.el6_6.x86_64.rpm rpm-libs-4.8.0-38.el6_6.i686.rpm rpm-libs-4.8.0-38.el6_6.x86_64.rpm rpm-python-4.8.0-38.el6_6.x86_64.rpm rpm-devel-4.8.0-38.el6_6.i686.rpm rpm-devel-4.8.0-38.el6_6.x86_64.rpm i386 rpm-4.8.0-38.el6_6.i686.rpm rpm-build-4.8.0-38.el6_6.i686.rpm rpm-debuginfo-4.8.0-38.el6_6.i686.rpm rpm-libs-4.8.0-38.el6_6.i686.rpm rpm-python-4.8.0-38.el6_6.i686.rpm rpm-devel-4.8.0-38.el6_6.i686.rpm noarch rpm-apidocs-4.8.0-38.el6_6.noarch.rpm rpm-cron-4.8.0-38.el6_6.noarch.rpm - Scientific Linux Development Team
Important: rpm security update