Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

Ubuntu 12.04 LTS USN-1695-1 Addresses Moderate RPM Crash Vulnerability

ubuntu
Calendar Grey January 17, 2013
Scroller Ubuntu
Mitigating RPM weaknesses in Ubuntu is crucial to avoid software failures and security threats linked to specially designed files.
RPM could be made to crash or run programs if it opened a specially crafted package file.

Summary

RPM could be made to crash or run programs if it opened a specially crafted

package file.

Software Description:

- rpm: package manager for RPM

Details:

It was discovered that RPM incorrectly handled certain package headers. If

a user or automated system were tricked into installing a specially crafted

RPM package, an attacker could cause RPM to crash, resulting in a denial of

service, or possibly execute arbitrary code.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 LTS:
  rpm                             4.9.1.1-1ubuntu0.1

Ubuntu 11.10:
  rpm                             4.9.0-7ubuntu0.1

Ubuntu 10.04 LTS:
  rpm                             4.7.2-1lubuntu0.1

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1695-1

CVE-2011-3378, CVE-2012-0060, CVE-2012-0061, CVE-2012-0815

January 17, 2013

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.