rpm package
opensuse/rpm-plugin-imaevmsign&distro=openSUSE Leap 16.0
pkg:rpm/opensuse/rpm-plugin-imaevmsign&distro=openSUSE%20Leap%2016.0
Vulnerabilities (2)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-44605 | Med | 5.5 | < 4.20.1-160000.3.1 | 4.20.1-160000.3.1 | Aug 5, 2026 | A flaw was found in the RPM Package Manager (RPM). A local user could be affected by a heap buffer overflow vulnerability when processing a specially crafted NDB database file. This issue arises from an error in how RPM handles certain calculations during file parsing, leading to | |
| CVE-2026-44604 | Hig | 7.0 | < 4.20.1-160000.3.1 | 4.20.1-160000.3.1 | May 28, 2026 | A command injection vulnerability was discovered in the `rpmuncompress` utility of RPM. When extracting certain archive formats (ZIP, 7z, GEM) to a specified destination directory, the tool inserts the archive's top-level folder name into a shell command without properly sanitizi |
- affected < 4.20.1-160000.3.1fixed 4.20.1-160000.3.1
A flaw was found in the RPM Package Manager (RPM). A local user could be affected by a heap buffer overflow vulnerability when processing a specially crafted NDB database file. This issue arises from an error in how RPM handles certain calculations during file parsing, leading to
- affected < 4.20.1-160000.3.1fixed 4.20.1-160000.3.1
A command injection vulnerability was discovered in the `rpmuncompress` utility of RPM. When extracting certain archive formats (ZIP, 7z, GEM) to a specified destination directory, the tool inserts the archive's top-level folder name into a shell command without properly sanitizi