VYPR

rpm package

opensuse/python-rpm&distro=openSUSE Leap 16.0

pkg:rpm/opensuse/python-rpm&distro=openSUSE%20Leap%2016.0

Vulnerabilities (2)

  • CVE-2026-44605MedAug 5, 2026
    affected < 4.20.1-160000.3.1fixed 4.20.1-160000.3.1

    A flaw was found in the RPM Package Manager (RPM). A local user could be affected by a heap buffer overflow vulnerability when processing a specially crafted NDB database file. This issue arises from an error in how RPM handles certain calculations during file parsing, leading to

  • CVE-2026-44604HigMay 28, 2026
    affected < 4.20.1-160000.3.1fixed 4.20.1-160000.3.1

    A command injection vulnerability was discovered in the `rpmuncompress` utility of RPM. When extracting certain archive formats (ZIP, 7z, GEM) to a specified destination directory, the tool inserts the archive's top-level folder name into a shell command without properly sanitizi