VYPR

Package Manager

by Red Hat

CVEs (3)

  • CVE-2017-3224HigJul 24, 2018
    risk 0.53cvss 8.2epss 0.01

    Open Shortest Path First (OSPF) protocol implementations may improperly determine Link State Advertisement (LSA) recency for LSAs with MaxSequenceNumber. According to RFC 2328 section 13.1, for two instances of the same LSA, recency is determined by first comparing sequence…

  • CVE-2002-2204Dec 31, 2002
    risk 0.00cvss —epss 0.02

    The default --checksig setting in RPM Package Manager 4.0.4 checks that a package's signature is valid without listing who signed it, which can allow remote attackers to make it appear that a malicious package comes from a trusted source.

  • CVE-2001-0923Oct 25, 2001
    risk 0.00cvss —epss 0.01

    RPM Package Manager 4.0.x through 4.0.2.x allows an attacker to execute arbitrary code via corrupted data in the RPM file when the file is queried.