MEDIUM · 5.4

CVE-2006-5466

Heap-based buffer overflow in the showQueryPackage function in librpm in RPM Package Manager 4.4.8, when the LANG environment variable is set to ru_RU.UTF-8, might allow user-assisted attackers to exe...

Vulnerability Description

Heap-based buffer overflow in the showQueryPackage function in librpm in RPM Package Manager 4.4.8, when the LANG environment variable is set to ru_RU.UTF-8, might allow user-assisted attackers to execute arbitrary code via crafted RPM packages.

CVSS Score

5.4

MEDIUM

AV:N/AC:H/Au:N/C:N/I:N/A:C
Confidentiality
NONE
Integrity
NONE
Availability
COMPLETE

Affected Products

VendorProductVersions
RpmPackage Manager4.4.8
UbuntuUbuntu Linux6.06_lts

References

FAQ

What is CVE-2006-5466?

CVE-2006-5466 is a vulnerability with a CVSS score of 5.4 (MEDIUM). Heap-based buffer overflow in the showQueryPackage function in librpm in RPM Package Manager 4.4.8, when the LANG environment variable is set to ru_RU.UTF-8, might allow user-assisted attackers to exe...

How severe is CVE-2006-5466?

CVE-2006-5466 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2006-5466?

Check the references section above for vendor advisories and patch information. Affected products include: Rpm Package Manager, Ubuntu Ubuntu Linux.