arr-pm
This library allows to you to read and write rpm packages. Written in pure ruby because librpm is not available on all systems
Activity
- Latest release
- 3y ago
- Total releases
- 11
- Cadence
- ~5 months
- Last 12 months
- 0
Details
- License
- Apache-2.0
- First release
- Mar 08, 2012
| Version | Released | |
|---|---|---|
0.0.12
patch
|
0.0.12
patch
Dependencies (4)
|
|
0.0.11
patch
1 CVE
CVE-2022-39224
GHSA-88cv-mj24-8w3q
Sep 21, 2022
arr-pm vulnerable to arbitrary shell execution when extracting or listing files contained in a malicious rpm.
7.0
/ 10
High
Local
High
None
Required
Unchanged
High
High
High
ImpactArbitrary shell execution is possible when using RPM::File#files and RPM::File#extract if the RPM contains a malicious "payload compressor" field. This vulnerability impacts the PatchesVersion 0.0.12 is available with a fix for these issues. WorkaroundsWhen using an affected version of this library (arr-pm), ensure any RPMs being processed contain valid/known payload compressor values. Such values include: gzip, bzip2, xz, zstd, and lzma. You can check the payload compressor field in an rpm by using the rpm command line tool. For example:
Impact on known dependent projectsThis library is used by fpm. The vulnerability may impact fpm only when using the flag References
CreditThanks to @joernchen for reporting this problem and contributing to the resolution :) For more informationIf you have any questions or comments about this advisory:
Affected versions
0.0.10
0.0.11
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
Fixed in
0.0.12
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.0.11
patch
Dependencies (2)
|
|
0.0.10
patch
1 CVE
CVE-2022-39224
GHSA-88cv-mj24-8w3q
Sep 21, 2022
arr-pm vulnerable to arbitrary shell execution when extracting or listing files contained in a malicious rpm.
7.0
/ 10
High
Local
High
None
Required
Unchanged
High
High
High
ImpactArbitrary shell execution is possible when using RPM::File#files and RPM::File#extract if the RPM contains a malicious "payload compressor" field. This vulnerability impacts the PatchesVersion 0.0.12 is available with a fix for these issues. WorkaroundsWhen using an affected version of this library (arr-pm), ensure any RPMs being processed contain valid/known payload compressor values. Such values include: gzip, bzip2, xz, zstd, and lzma. You can check the payload compressor field in an rpm by using the rpm command line tool. For example:
Impact on known dependent projectsThis library is used by fpm. The vulnerability may impact fpm only when using the flag References
CreditThanks to @joernchen for reporting this problem and contributing to the resolution :) For more informationIf you have any questions or comments about this advisory:
Affected versions
0.0.10
0.0.11
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
Fixed in
0.0.12
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.0.10
patch
Dependencies (2)
|
|
0.0.9
patch
1 CVE
CVE-2022-39224
GHSA-88cv-mj24-8w3q
Sep 21, 2022
arr-pm vulnerable to arbitrary shell execution when extracting or listing files contained in a malicious rpm.
7.0
/ 10
High
Local
High
None
Required
Unchanged
High
High
High
ImpactArbitrary shell execution is possible when using RPM::File#files and RPM::File#extract if the RPM contains a malicious "payload compressor" field. This vulnerability impacts the PatchesVersion 0.0.12 is available with a fix for these issues. WorkaroundsWhen using an affected version of this library (arr-pm), ensure any RPMs being processed contain valid/known payload compressor values. Such values include: gzip, bzip2, xz, zstd, and lzma. You can check the payload compressor field in an rpm by using the rpm command line tool. For example:
Impact on known dependent projectsThis library is used by fpm. The vulnerability may impact fpm only when using the flag References
CreditThanks to @joernchen for reporting this problem and contributing to the resolution :) For more informationIf you have any questions or comments about this advisory:
Affected versions
0.0.10
0.0.11
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
Fixed in
0.0.12
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.0.9
patch
Dependencies (1)
|
|
0.0.8
patch
1 CVE
CVE-2022-39224
GHSA-88cv-mj24-8w3q
Sep 21, 2022
arr-pm vulnerable to arbitrary shell execution when extracting or listing files contained in a malicious rpm.
7.0
/ 10
High
Local
High
None
Required
Unchanged
High
High
High
ImpactArbitrary shell execution is possible when using RPM::File#files and RPM::File#extract if the RPM contains a malicious "payload compressor" field. This vulnerability impacts the PatchesVersion 0.0.12 is available with a fix for these issues. WorkaroundsWhen using an affected version of this library (arr-pm), ensure any RPMs being processed contain valid/known payload compressor values. Such values include: gzip, bzip2, xz, zstd, and lzma. You can check the payload compressor field in an rpm by using the rpm command line tool. For example:
Impact on known dependent projectsThis library is used by fpm. The vulnerability may impact fpm only when using the flag References
CreditThanks to @joernchen for reporting this problem and contributing to the resolution :) For more informationIf you have any questions or comments about this advisory:
Affected versions
0.0.10
0.0.11
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
Fixed in
0.0.12
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.0.8
patch
Dependencies (1)
|
|
0.0.7
patch
1 CVE
CVE-2022-39224
GHSA-88cv-mj24-8w3q
Sep 21, 2022
arr-pm vulnerable to arbitrary shell execution when extracting or listing files contained in a malicious rpm.
7.0
/ 10
High
Local
High
None
Required
Unchanged
High
High
High
ImpactArbitrary shell execution is possible when using RPM::File#files and RPM::File#extract if the RPM contains a malicious "payload compressor" field. This vulnerability impacts the PatchesVersion 0.0.12 is available with a fix for these issues. WorkaroundsWhen using an affected version of this library (arr-pm), ensure any RPMs being processed contain valid/known payload compressor values. Such values include: gzip, bzip2, xz, zstd, and lzma. You can check the payload compressor field in an rpm by using the rpm command line tool. For example:
Impact on known dependent projectsThis library is used by fpm. The vulnerability may impact fpm only when using the flag References
CreditThanks to @joernchen for reporting this problem and contributing to the resolution :) For more informationIf you have any questions or comments about this advisory:
Affected versions
0.0.10
0.0.11
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
Fixed in
0.0.12
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.0.7
patch
Dependencies (1)
|
|
0.0.5
patch
1 CVE
CVE-2022-39224
GHSA-88cv-mj24-8w3q
Sep 21, 2022
arr-pm vulnerable to arbitrary shell execution when extracting or listing files contained in a malicious rpm.
7.0
/ 10
High
Local
High
None
Required
Unchanged
High
High
High
ImpactArbitrary shell execution is possible when using RPM::File#files and RPM::File#extract if the RPM contains a malicious "payload compressor" field. This vulnerability impacts the PatchesVersion 0.0.12 is available with a fix for these issues. WorkaroundsWhen using an affected version of this library (arr-pm), ensure any RPMs being processed contain valid/known payload compressor values. Such values include: gzip, bzip2, xz, zstd, and lzma. You can check the payload compressor field in an rpm by using the rpm command line tool. For example:
Impact on known dependent projectsThis library is used by fpm. The vulnerability may impact fpm only when using the flag References
CreditThanks to @joernchen for reporting this problem and contributing to the resolution :) For more informationIf you have any questions or comments about this advisory:
Affected versions
0.0.10
0.0.11
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
Fixed in
0.0.12
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.0.5
patch
Dependencies (1)
|
|
0.0.6
patch
1 CVE
CVE-2022-39224
GHSA-88cv-mj24-8w3q
Sep 21, 2022
arr-pm vulnerable to arbitrary shell execution when extracting or listing files contained in a malicious rpm.
7.0
/ 10
High
Local
High
None
Required
Unchanged
High
High
High
ImpactArbitrary shell execution is possible when using RPM::File#files and RPM::File#extract if the RPM contains a malicious "payload compressor" field. This vulnerability impacts the PatchesVersion 0.0.12 is available with a fix for these issues. WorkaroundsWhen using an affected version of this library (arr-pm), ensure any RPMs being processed contain valid/known payload compressor values. Such values include: gzip, bzip2, xz, zstd, and lzma. You can check the payload compressor field in an rpm by using the rpm command line tool. For example:
Impact on known dependent projectsThis library is used by fpm. The vulnerability may impact fpm only when using the flag References
CreditThanks to @joernchen for reporting this problem and contributing to the resolution :) For more informationIf you have any questions or comments about this advisory:
Affected versions
0.0.10
0.0.11
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
Fixed in
0.0.12
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.0.6
patch
Dependencies (1)
|
|
0.0.4
patch
1 CVE
CVE-2022-39224
GHSA-88cv-mj24-8w3q
Sep 21, 2022
arr-pm vulnerable to arbitrary shell execution when extracting or listing files contained in a malicious rpm.
7.0
/ 10
High
Local
High
None
Required
Unchanged
High
High
High
ImpactArbitrary shell execution is possible when using RPM::File#files and RPM::File#extract if the RPM contains a malicious "payload compressor" field. This vulnerability impacts the PatchesVersion 0.0.12 is available with a fix for these issues. WorkaroundsWhen using an affected version of this library (arr-pm), ensure any RPMs being processed contain valid/known payload compressor values. Such values include: gzip, bzip2, xz, zstd, and lzma. You can check the payload compressor field in an rpm by using the rpm command line tool. For example:
Impact on known dependent projectsThis library is used by fpm. The vulnerability may impact fpm only when using the flag References
CreditThanks to @joernchen for reporting this problem and contributing to the resolution :) For more informationIf you have any questions or comments about this advisory:
Affected versions
0.0.10
0.0.11
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
Fixed in
0.0.12
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.0.4
patch
Dependencies (1)
|
|
0.0.3
patch
1 CVE
CVE-2022-39224
GHSA-88cv-mj24-8w3q
Sep 21, 2022
arr-pm vulnerable to arbitrary shell execution when extracting or listing files contained in a malicious rpm.
7.0
/ 10
High
Local
High
None
Required
Unchanged
High
High
High
ImpactArbitrary shell execution is possible when using RPM::File#files and RPM::File#extract if the RPM contains a malicious "payload compressor" field. This vulnerability impacts the PatchesVersion 0.0.12 is available with a fix for these issues. WorkaroundsWhen using an affected version of this library (arr-pm), ensure any RPMs being processed contain valid/known payload compressor values. Such values include: gzip, bzip2, xz, zstd, and lzma. You can check the payload compressor field in an rpm by using the rpm command line tool. For example:
Impact on known dependent projectsThis library is used by fpm. The vulnerability may impact fpm only when using the flag References
CreditThanks to @joernchen for reporting this problem and contributing to the resolution :) For more informationIf you have any questions or comments about this advisory:
Affected versions
0.0.10
0.0.11
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
Fixed in
0.0.12
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.0.3
patch
Dependencies (1)
|
|
0.0.2
initial
1 CVE
CVE-2022-39224
GHSA-88cv-mj24-8w3q
Sep 21, 2022
arr-pm vulnerable to arbitrary shell execution when extracting or listing files contained in a malicious rpm.
7.0
/ 10
High
Local
High
None
Required
Unchanged
High
High
High
ImpactArbitrary shell execution is possible when using RPM::File#files and RPM::File#extract if the RPM contains a malicious "payload compressor" field. This vulnerability impacts the PatchesVersion 0.0.12 is available with a fix for these issues. WorkaroundsWhen using an affected version of this library (arr-pm), ensure any RPMs being processed contain valid/known payload compressor values. Such values include: gzip, bzip2, xz, zstd, and lzma. You can check the payload compressor field in an rpm by using the rpm command line tool. For example:
Impact on known dependent projectsThis library is used by fpm. The vulnerability may impact fpm only when using the flag References
CreditThanks to @joernchen for reporting this problem and contributing to the resolution :) For more informationIf you have any questions or comments about this advisory:
Affected versions
0.0.10
0.0.11
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
Fixed in
0.0.12
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.0.2
initial
Dependencies (1)
|