Heap-based buffer overflow in the showQueryPackage function in librpm in RPM Package Manager 4.4.8, when the LANG environment variable is set to ru_RU.UTF-8, might allow user-assisted attackers to execute arbitrary code via crafted RPM packages.
| Software | From | Fixed in |
|---|---|---|
| rpm / package_manager | 4.4.8 | 4.4.8.x |
| ubuntu / ubuntu_linux | 6.06_lts | 6.06_lts.x |
| ubuntu / ubuntu_linux | 6.10 | 6.10.x |