Back to bug 744104

Who When What Removed Added
Ramon de C Valle 2011-10-07 08:33:42 UTC Component rpm vulnerability
Version 6.1 unspecified
Assignee pmatilai security-response-team
Product Red Hat Enterprise Linux 6 Security Response
Target Milestone rc ---
QA Contact qe-baseos-security
Ramon de C Valle 2011-10-07 09:30:24 UTC Whiteboard impact=important,public=no,reported=20111007,source=redhat,cvss2=7.6/AV:N/AC:H/Au:N/C:C/I:C/A:C,rhel-5.3.z/rpm=affected,rhel-3/rpm=affected,rhel-4/rpm=affected,rhel-5.6.z/rpm=affected,rhel-5/rpm=affected,rhel-6.0.z/rpm=affected,rhel-6/rpm=affected, fedora-13/rpm=affected,fedora-14/rpm=affected,fedora-15/rpm=notaffected
Ramon de C Valle 2011-10-07 09:31:21 UTC Whiteboard impact=important,public=no,reported=20111007,source=redhat,cvss2=7.6/AV:N/AC:H/Au:N/C:C/I:C/A:C,rhel-5.3.z/rpm=affected,rhel-3/rpm=affected,rhel-4/rpm=affected,rhel-5.6.z/rpm=affected,rhel-5/rpm=affected,rhel-6.0.z/rpm=affected,rhel-6/rpm=affected, fedora-13/rpm=affected,fedora-14/rpm=affected,fedora-15/rpm=notaffected impact=important,public=no,reported=20111007,source=redhat,cvss2=7.6/AV:N/AC:H/Au:N/C:C/I:C/A:C,rhel-5.3.z/rpm=affected,rhel-3/rpm=affected,rhel-4/rpm=affected,rhel-5.6.z/rpm=affected,rhel-5/rpm=affected,rhel-6.0.z/rpm=affected,rhel-6/rpm=affected fedora-13/rpm=affected,fedora-14/rpm=affected,fedora-15/rpm=notaffected
Ramon de C Valle 2011-10-07 09:53:56 UTC Whiteboard impact=important,public=no,reported=20111007,source=redhat,cvss2=7.6/AV:N/AC:H/Au:N/C:C/I:C/A:C,rhel-5.3.z/rpm=affected,rhel-3/rpm=affected,rhel-4/rpm=affected,rhel-5.6.z/rpm=affected,rhel-5/rpm=affected,rhel-6.0.z/rpm=affected,rhel-6/rpm=affected fedora-13/rpm=affected,fedora-14/rpm=affected,fedora-15/rpm=notaffected impact=important,public=no,reported=20111007,source=redhat,cvss2=7.6/AV:N/AC:H/Au:N/C:C/I:C/A:C,rhel-5.3.z/rpm=affected,rhel-3/rpm=affected,rhel-4/rpm=affected,rhel-5.6.z/rpm=affected,rhel-5/rpm=affected,rhel-6.0.z/rpm=affected,rhel-6/rpm=affected fedora-14/rpm=affected,fedora-15/rpm=notaffected
Ramon de C Valle 2011-10-07 13:20:53 UTC Blocks 744203
Ramon de C Valle 2011-10-07 17:21:42 UTC CC pmatilai
Ramon de C Valle 2011-10-07 17:23:00 UTC CC jnovy
Ramon de C Valle 2011-10-10 12:32:58 UTC Alias CVE-2011-3608
Ramon de C Valle 2011-10-10 12:33:01 UTC Summary rpm: RPM rpmpkgReadHeader numeric range comparison without minimum check CVE-2011-3608 rpm: RPM rpmpkgReadHeader numeric range comparison without minimum check
Ramon de C Valle 2011-10-10 15:04:12 UTC Priority urgent high
Severity urgent high
Tomas Hoger 2011-10-10 15:07:54 UTC Group qe_staff
Ramon de C Valle 2011-10-10 17:07:55 UTC Summary CVE-2011-3608 rpm: RPM rpmpkgReadHeader numeric range comparison without minimum check EMBARGOED CVE-2011-3608 rpm: RPM rpmpkgReadHeader numeric range comparison without minimum check
Ramon de C Valle 2012-01-26 16:14:48 UTC Whiteboard impact=important,public=no,reported=20111007,source=redhat,cvss2=7.6/AV:N/AC:H/Au:N/C:C/I:C/A:C,rhel-5.3.z/rpm=affected,rhel-3/rpm=affected,rhel-4/rpm=affected,rhel-5.6.z/rpm=affected,rhel-5/rpm=affected,rhel-6.0.z/rpm=affected,rhel-6/rpm=affected fedora-14/rpm=affected,fedora-15/rpm=notaffected impact=important,public=no,reported=20111007,source=redhat,cvss2=7.6/AV:N/AC:H/Au:N/C:C/I:C/A:C,rhel-4/rpm=affected,rhel-5/rpm=affected,rhel-6/rpm=notaffected,fedora-15/rpm=notaffected,fedora-16/rpm=notaffected
Ramon de C Valle 2012-01-26 16:15:27 UTC Summary EMBARGOED CVE-2011-3608 rpm: RPM rpmpkgReadHeader numeric range comparison without minimum check EMBARGOED CVE-2011-3608 rpm: headerVerifyInfo numeric range comparison without minimum check
Ramon de C Valle 2012-01-27 11:03:10 UTC Whiteboard impact=important,public=no,reported=20111007,source=redhat,cvss2=7.6/AV:N/AC:H/Au:N/C:C/I:C/A:C,rhel-4/rpm=affected,rhel-5/rpm=affected,rhel-6/rpm=notaffected,fedora-15/rpm=notaffected,fedora-16/rpm=notaffected impact=important,public=no,reported=20111007,source=redhat,cvss2=7.6/AV:N/AC:H/Au:N/C:C/I:C/A:C,rhel-4/rpm=affected,rhel-5/rpm=affected,rhel-6/rpm=notaffected,fedora-all=notaffected
Ramon de C Valle 2012-01-27 11:16:14 UTC Whiteboard impact=important,public=no,reported=20111007,source=redhat,cvss2=7.6/AV:N/AC:H/Au:N/C:C/I:C/A:C,rhel-4/rpm=affected,rhel-5/rpm=affected,rhel-6/rpm=notaffected,fedora-all=notaffected impact=important,public=no,reported=20111007,source=redhat,cvss2=7.6/AV:N/AC:H/Au:N/C:C/I:C/A:C,rhel-4/rpm=affected,rhel-5/rpm=affected,rhel-6/rpm=notaffected
Ramon de C Valle 2012-01-27 11:17:01 UTC Depends On 785109
Ramon de C Valle 2012-01-27 11:17:26 UTC Depends On 785110
Ramon de C Valle 2012-01-27 11:17:52 UTC Depends On 785111
Ramon de C Valle 2012-01-27 14:53:06 UTC Whiteboard impact=important,public=no,reported=20111007,source=redhat,cvss2=7.6/AV:N/AC:H/Au:N/C:C/I:C/A:C,rhel-4/rpm=affected,rhel-5/rpm=affected,rhel-6/rpm=notaffected impact=important,public=no,reported=20111007,source=redhat,cvss2=7.6/AV:N/AC:H/Au:N/C:C/I:C/A:C,rhel-4/rpm=affected,rhel-5/rpm=affected,rhel-6/rpm=notaffected,fedora-all/rpm=notaffected
Kurt Seifried 2012-01-27 16:51:08 UTC Summary EMBARGOED CVE-2011-3608 rpm: headerVerifyInfo numeric range comparison without minimum check EMBARGOED CVE-2012-0815 rpm: headerVerifyInfo numeric range comparison without minimum check
Alias CVE-2011-3608 CVE-2012-0815
Ramon de C Valle 2012-01-30 12:22:30 UTC Whiteboard impact=important,public=no,reported=20111007,source=redhat,cvss2=7.6/AV:N/AC:H/Au:N/C:C/I:C/A:C,rhel-4/rpm=affected,rhel-5/rpm=affected,rhel-6/rpm=notaffected,fedora-all/rpm=notaffected impact=important,public=20120215,reported=20111007,source=redhat,cvss2=7.6/AV:N/AC:H/Au:N/C:C/I:C/A:C,rhel-4/rpm=affected,rhel-5/rpm=affected,rhel-6/rpm=notaffected,fedora-all/rpm=notaffected
Ramon de C Valle 2012-01-30 15:12:13 UTC Whiteboard impact=important,public=20120215,reported=20111007,source=redhat,cvss2=7.6/AV:N/AC:H/Au:N/C:C/I:C/A:C,rhel-4/rpm=affected,rhel-5/rpm=affected,rhel-6/rpm=notaffected,fedora-all/rpm=notaffected impact=important,public=20120301,reported=20111007,source=redhat,cvss2=7.6/AV:N/AC:H/Au:N/C:C/I:C/A:C,rhel-3/rpm=affected,rhel-4/rpm=affected,rhel-5/rpm=affected,rhel-6/rpm=notaffected,fedora-all/rpm=notaffected
Ramon de C Valle 2012-01-30 15:25:26 UTC Depends On 785769
Ramon de C Valle 2012-01-30 15:34:17 UTC Depends On 785769
Whiteboard impact=important,public=20120301,reported=20111007,source=redhat,cvss2=7.6/AV:N/AC:H/Au:N/C:C/I:C/A:C,rhel-3/rpm=affected,rhel-4/rpm=affected,rhel-5/rpm=affected,rhel-6/rpm=notaffected,fedora-all/rpm=notaffected impact=important,public=20120301,reported=20111007,source=redhat,cvss2=7.6/AV:N/AC:H/Au:N/C:C/I:C/A:C,rhel-3/rpm=affected,rhel-4/rpm=affected,rhel-5/rpm=affected,rhel-6/rpm=affected,fedora-all/rpm=notaffected
Ramon de C Valle 2012-01-30 15:35:18 UTC Depends On 785112
Ramon de C Valle 2012-01-30 15:35:45 UTC Depends On 785113
Ramon de C Valle 2012-01-30 15:46:52 UTC Depends On 785769
Ramon de C Valle 2012-01-30 16:34:59 UTC Whiteboard impact=important,public=20120301,reported=20111007,source=redhat,cvss2=7.6/AV:N/AC:H/Au:N/C:C/I:C/A:C,rhel-3/rpm=affected,rhel-4/rpm=affected,rhel-5/rpm=affected,rhel-6/rpm=affected,fedora-all/rpm=notaffected impact=important,public=20120301,reported=20111007,source=redhat,cvss2=7.6/AV:N/AC:H/Au:N/C:C/I:C/A:C,rhel-3/rpm=affected,rhel-4/rpm=affected,rhel-5/rpm=affected,rhel-6/rpm=affected,fedora-all/rpm=notaffected,rhel-5.6/rpm=affected,rhel-6.0/rpm=affected rhel-6.1/rpm=affected
Ramon de C Valle 2012-01-30 16:40:48 UTC Depends On 785803
Ramon de C Valle 2012-01-30 16:41:05 UTC Depends On 785805
Ramon de C Valle 2012-01-30 16:42:20 UTC Depends On 785807
Ramon de C Valle 2012-01-30 19:22:40 UTC Whiteboard impact=important,public=20120301,reported=20111007,source=redhat,cvss2=7.6/AV:N/AC:H/Au:N/C:C/I:C/A:C,rhel-3/rpm=affected,rhel-4/rpm=affected,rhel-5/rpm=affected,rhel-6/rpm=affected,fedora-all/rpm=notaffected,rhel-5.6/rpm=affected,rhel-6.0/rpm=affected rhel-6.1/rpm=affected impact=important,public=20120301,reported=20111007,source=redhat,cvss2=7.6/AV:N/AC:H/Au:N/C:C/I:C/A:C,rhel-3/rpm=affected,rhel-4/rpm=affected,rhel-5/rpm=affected,rhel-6/rpm=affected,fedora-all/rpm=notaffected,rhel-5.3/rpm=affected,rhel-5.6/rpm=affected rhel-6.0/rpm=affected,rhel-6.1/rpm=affected
Ramon de C Valle 2012-01-30 19:26:04 UTC Whiteboard impact=important,public=20120301,reported=20111007,source=redhat,cvss2=7.6/AV:N/AC:H/Au:N/C:C/I:C/A:C,rhel-3/rpm=affected,rhel-4/rpm=affected,rhel-5/rpm=affected,rhel-6/rpm=affected,fedora-all/rpm=notaffected,rhel-5.3/rpm=affected,rhel-5.6/rpm=affected rhel-6.0/rpm=affected,rhel-6.1/rpm=affected impact=important,public=20120301,reported=20111007,source=redhat,cvss2=7.6/AV:N/AC:H/Au:N/C:C/I:C/A:C,rhel-3/rpm=affected,rhel-4/rpm=affected,rhel-5/rpm=affected,rhel-6/rpm=affected,fedora-all/rpm=affected,rhel-5.3/rpm=affected,rhel-5.6/rpm=affected rhel-6.0/rpm=affected,rhel-6.1/rpm=affected
Ramon de C Valle 2012-01-30 19:30:16 UTC Whiteboard impact=important,public=20120301,reported=20111007,source=redhat,cvss2=7.6/AV:N/AC:H/Au:N/C:C/I:C/A:C,rhel-3/rpm=affected,rhel-4/rpm=affected,rhel-5/rpm=affected,rhel-6/rpm=affected,fedora-all/rpm=affected,rhel-5.3/rpm=affected,rhel-5.6/rpm=affected rhel-6.0/rpm=affected,rhel-6.1/rpm=affected impact=important,public=20120301,reported=20111007,source=redhat,cvss2=7.6/AV:N/AC:H/Au:N/C:C/I:C/A:C,rhel-3/rpm=affected,rhel-4/rpm=affected,rhel-5/rpm=affected,rhel-6/rpm=affected,fedora-all/rpm=affected,rhel-5.3.z/rpm=affected,rhel-5.6/rpm=affected rhel-6.0/rpm=affected,rhel-6.1/rpm=affected
Ramon de C Valle 2012-01-30 19:31:07 UTC Depends On 785862
Ramon de C Valle 2012-01-30 19:40:24 UTC Whiteboard impact=important,public=20120301,reported=20111007,source=redhat,cvss2=7.6/AV:N/AC:H/Au:N/C:C/I:C/A:C,rhel-3/rpm=affected,rhel-4/rpm=affected,rhel-5/rpm=affected,rhel-6/rpm=affected,fedora-all/rpm=affected,rhel-5.3.z/rpm=affected,rhel-5.6/rpm=affected rhel-6.0/rpm=affected,rhel-6.1/rpm=affected impact=important,public=20120301,reported=20111007,source=redhat,cvss2=7.6/AV:N/AC:H/Au:N/C:C/I:C/A:C,rhel-3/rpm=affected,rhel-4/rpm=affected,rhel-5/rpm=affected,rhel-6/rpm=affected,fedora-all/rpm=affected,rhel-5.6.z/rpm=affected,rhel-6.0.z/rpm=affected rhel-6.1.z/rpm=affected,rhel-5.3.z/rpm=affected
Tomas Hoger 2012-02-29 11:03:33 UTC Summary EMBARGOED CVE-2012-0815 rpm: headerVerifyInfo numeric range comparison without minimum check EMBARGOED CVE-2012-0815 rpm: incorrect handling of negated offsets in headerVerifyInfo()
Tomas Hoger 2012-02-29 11:09:36 UTC Whiteboard impact=important,public=20120301,reported=20111007,source=redhat,cvss2=7.6/AV:N/AC:H/Au:N/C:C/I:C/A:C,rhel-3/rpm=affected,rhel-4/rpm=affected,rhel-5/rpm=affected,rhel-6/rpm=affected,fedora-all/rpm=affected,rhel-5.6.z/rpm=affected,rhel-6.0.z/rpm=affected rhel-6.1.z/rpm=affected,rhel-5.3.z/rpm=affected impact=important,public=20120301,reported=20111007,source=redhat,cvss2=7.6/AV:N/AC:H/Au:N/C:C/I:C/A:C,rhel-3/rpm=affected,rhel-4/rpm=affected,rhel-5.3.z/rpm=affected,rhel-5.6.z/rpm=affected,rhel-5/rpm=affected,rhel-6.0.z/rpm=affected rhel-6.1.z/rpm=affected,rhel-6/rpm=affected,fedora-all/rpm=affected
Tomas Hoger 2012-03-27 12:49:18 UTC Whiteboard impact=important,public=20120301,reported=20111007,source=redhat,cvss2=7.6/AV:N/AC:H/Au:N/C:C/I:C/A:C,rhel-3/rpm=affected,rhel-4/rpm=affected,rhel-5.3.z/rpm=affected,rhel-5.6.z/rpm=affected,rhel-5/rpm=affected,rhel-6.0.z/rpm=affected rhel-6.1.z/rpm=affected,rhel-6/rpm=affected,fedora-all/rpm=affected impact=important,public=20120403,reported=20111007,source=redhat,cvss2=7.6/AV:N/AC:H/Au:N/C:C/I:C/A:C,rhel-3/rpm=affected,rhel-4/rpm=affected,rhel-5.3.z/rpm=affected,rhel-5.6.z/rpm=affected,rhel-5/rpm=affected,rhel-6.0.z/rpm=affected rhel-6.1.z/rpm=affected,rhel-6/rpm=affected,fedora-all/rpm=affected
Ramon de C Valle 2012-03-28 17:25:29 UTC Whiteboard impact=important,public=20120403,reported=20111007,source=redhat,cvss2=7.6/AV:N/AC:H/Au:N/C:C/I:C/A:C,rhel-3/rpm=affected,rhel-4/rpm=affected,rhel-5.3.z/rpm=affected,rhel-5.6.z/rpm=affected,rhel-5/rpm=affected,rhel-6.0.z/rpm=affected rhel-6.1.z/rpm=affected,rhel-6/rpm=affected,fedora-all/rpm=affected impact=important,public=20120403,reported=20111007,source=redhat,cvss2=7.6/AV:N/AC:H/Au:N/C:C/I:C/A:C,rhel-3/rpm=affected,rhel-4/rpm=affected,rhel-5.3.z/rpm=affected,rhel-5.6.z/rpm=affected,rhel-5/rpm=affected,rhel-6.0.z/rpm=affected rhel-6.1.z/rpm=affected,rhel-6/rpm=affected,fedora-all/rpm=affected,cwe=CWE-120
Ramon de C Valle 2012-03-28 17:26:20 UTC Whiteboard impact=important,public=20120403,reported=20111007,source=redhat,cvss2=7.6/AV:N/AC:H/Au:N/C:C/I:C/A:C,rhel-3/rpm=affected,rhel-4/rpm=affected,rhel-5.3.z/rpm=affected,rhel-5.6.z/rpm=affected,rhel-5/rpm=affected,rhel-6.0.z/rpm=affected rhel-6.1.z/rpm=affected,rhel-6/rpm=affected,fedora-all/rpm=affected,cwe=CWE-120 impact=important,public=20120403,reported=20111007,source=redhat,cvss2=7.6/AV:N/AC:H/Au:N/C:C/I:C/A:C,rhel-3/rpm=affected,rhel-4/rpm=affected,rhel-5.3.z/rpm=affected,rhel-5.6.z/rpm=affected,rhel-5/rpm=affected,rhel-6.0.z/rpm=affected rhel-6.1.z/rpm=affected,rhel-6/rpm=affected,fedora-all/rpm=affected,cwe=CWE-682/CWE-120
Patrik Kis 2012-03-29 08:16:25 UTC CC pkis
Tomas Hoger 2012-04-03 13:31:32 UTC Group security, qe_staff
Summary EMBARGOED CVE-2012-0815 rpm: incorrect handling of negated offsets in headerVerifyInfo() CVE-2012-0815 rpm: incorrect handling of negated offsets in headerVerifyInfo()
Tomas Hoger 2012-04-03 13:38:40 UTC Depends On 809487
Tomas Hoger 2012-04-03 14:18:33 UTC Fixed In Version rpm 4.9.1.3
devzero2000 2012-04-05 10:41:52 UTC CC pinto.elia
Ramon de C Valle 2012-04-26 15:12:16 UTC Whiteboard impact=important,public=20120403,reported=20111007,source=redhat,cvss2=7.6/AV:N/AC:H/Au:N/C:C/I:C/A:C,rhel-3/rpm=affected,rhel-4/rpm=affected,rhel-5.3.z/rpm=affected,rhel-5.6.z/rpm=affected,rhel-5/rpm=affected,rhel-6.0.z/rpm=affected rhel-6.1.z/rpm=affected,rhel-6/rpm=affected,fedora-all/rpm=affected,cwe=CWE-682/CWE-120 impact=important,public=20120403,reported=20111007,source=redhat,cvss2=7.6/AV:N/AC:H/Au:N/C:C/I:C/A:C,rhel-3/rpm=affected,rhel-4/rpm=affected,rhel-5.3.z/rpm=affected,rhel-5.6.z/rpm=affected,rhel-5/rpm=affected,rhel-6.0.z/rpm=affected rhel-6.1.z/rpm=affected,rhel-6/rpm=affected,fedora-all/rpm=affected,cwe=CWE-189/CWE-119
Tomas Hoger 2012-05-07 09:55:57 UTC Status NEW CLOSED
Resolution --- ERRATA
Last Closed 2012-05-07 05:55:57 UTC
Ramon de C Valle 2012-05-16 16:17:41 UTC Whiteboard impact=important,public=20120403,reported=20111007,source=redhat,cvss2=7.6/AV:N/AC:H/Au:N/C:C/I:C/A:C,rhel-3/rpm=affected,rhel-4/rpm=affected,rhel-5.3.z/rpm=affected,rhel-5.6.z/rpm=affected,rhel-5/rpm=affected,rhel-6.0.z/rpm=affected rhel-6.1.z/rpm=affected,rhel-6/rpm=affected,fedora-all/rpm=affected,cwe=CWE-189/CWE-119 impact=important,public=20120403,reported=20111007,source=redhat,cvss2=7.6/AV:N/AC:H/Au:N/C:C/I:C/A:C,rhel-3/rpm=affected,rhel-4/rpm=affected,rhel-5.3.z/rpm=affected,rhel-5.6.z/rpm=affected,rhel-5/rpm=affected,rhel-6.0.z/rpm=affected rhel-6.1.z/rpm=affected,rhel-6/rpm=affected,fedora-all/rpm=affected,cwe=CWE-839
Patrik Kis 2012-06-11 11:09:13 UTC Depends On 830759
Ramon de C Valle 2012-07-09 17:36:54 UTC Whiteboard impact=important,public=20120403,reported=20111007,source=redhat,cvss2=7.6/AV:N/AC:H/Au:N/C:C/I:C/A:C,rhel-3/rpm=affected,rhel-4/rpm=affected,rhel-5.3.z/rpm=affected,rhel-5.6.z/rpm=affected,rhel-5/rpm=affected,rhel-6.0.z/rpm=affected rhel-6.1.z/rpm=affected,rhel-6/rpm=affected,fedora-all/rpm=affected,cwe=CWE-839 impact=important,public=20120403,reported=20111007,source=redhat,cvss2=7.6/AV:N/AC:H/Au:N/C:C/I:C/A:C,rhel-3/rpm=affected,rhel-4/rpm=affected,rhel-5.3.z/rpm=affected,rhel-5.6.z/rpm=affected,rhel-5/rpm=affected,rhel-6.0.z/rpm=affected rhel-6.1.z/rpm=affected,rhel-6/rpm=affected,fedora-all/rpm=affected,cwe=CWE-839->CWE-119
John Skeoch 2013-10-14 01:01:32 UTC CC bressers
Product Security DevOps Team 2019-09-29 12:48:01 UTC Whiteboard impact=important,public=20120403,reported=20111007,source=redhat,cvss2=7.6/AV:N/AC:H/Au:N/C:C/I:C/A:C,rhel-3/rpm=affected,rhel-4/rpm=affected,rhel-5.3.z/rpm=affected,rhel-5.6.z/rpm=affected,rhel-5/rpm=affected,rhel-6.0.z/rpm=affected,rhel-6.1.z/rpm=affected,rhel-6/rpm=affected,fedora-all/rpm=affected,cwe=CWE-839->CWE-119

Back to bug 744104