CVE-2013-6435: Debian Linux
High severity, CVSS 7.6. EPSS: 7.6% chance of exploitation in the next 30 days.
Race condition in RPM 4.11.1 and earlier allows remote attackers to execute arbitrary code via a crafted RPM file whose installation extracts the contents to temporary files before validating the signature, as demonstrated by installing a file in the /etc/cron.d directory.
Affected products
- Debian Debian Linux: version 7.0 only
- Rpm Rpm: up to and including 4.11.1; version 1.2 only; version 1.3 only; version 1.3.1 only; version 1.4 only; version 1.4.1 only; …
Published 2014-12-16. Last modified 2026-06-17.