CVE-2013-6435: Debian Linux

High severity, CVSS 7.6. EPSS: 7.6% chance of exploitation in the next 30 days.

Race condition in RPM 4.11.1 and earlier allows remote attackers to execute arbitrary code via a crafted RPM file whose installation extracts the contents to temporary files before validating the signature, as demonstrated by installing a file in the /etc/cron.d directory.

Affected products

  • Debian Debian Linux: version 7.0 only
  • Rpm Rpm: up to and including 4.11.1; version 1.2 only; version 1.3 only; version 1.3.1 only; version 1.4 only; version 1.4.1 only; …

Published 2014-12-16. Last modified 2026-06-17.