Mandriva Linux Security Advisory : rpm (MDVSA-2011:143)
High Nessus Plugin ID 56403
SynopsisThe remote Mandriva Linux host is missing one or more security updates.
DescriptionMultiple flaws were found in the way the RPM library parsed package headers. An attacker could create a specially crafted RPM package that, when queried or installed, would cause rpm to crash or, potentially, execute arbitrary code (CVE-2011-3378).
Additionally for Mandriva Linux 2009.0 and Mandriva Linux Enterprise Server 5 updated perl-URPM and lzma (xz v5) packages are being provided to support upgrading to Mandriva Linux 2011.
The updated packages have been patched to correct these issues.
SolutionUpdate the affected packages.