7

CVE-2021-20271

A flaw was found in RPM's signature check functionality when reading a package file. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package, whose signature header was modified, to cause RPM database corruption and execute code. The highest threat from this vulnerability is to data integrity, confidentiality, and system availability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Rpm ≫ Rpm Version >= 4.15.0 < 4.15.1.3
Rpm ≫ Rpm Version >= 4.16.0 < 4.16.1.3
Rpm ≫ Rpm Version 4.15.0 Update alpha
Rpm ≫ Rpm Version 4.15.0 Update beta1
Rpm ≫ Rpm Version 4.15.0 Update rc1
Rpm ≫ Rpm Version 4.16.0 Update alpha
Rpm ≫ Rpm Version 4.16.0 Update beta2
Rpm ≫ Rpm Version 4.16.0 Update beta3
Rpm ≫ Rpm Version 4.16.0 Update rc1
Redhat ≫ Enterprise Linux Version 8.0
Fedoraproject ≫ Fedora Version 32
Fedoraproject ≫ Fedora Version 33
Fedoraproject ≫ Fedora Version 34
Starwindsoftware ≫ Starwind Virtual San Version v8 Update build14398
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.79% 0.526
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7 1 5.9
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
NIST 5.1 4.9 6.4
AV:N/AC:H/Au:N/C:P/I:P/A:P
CWE-345 Insufficient Verification of Data Authenticity

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

https://bugzilla.redhat.com/show_bug.cgi?id=1934125
Patch
Third Party Advisory
Issue Tracking
https://github.com/rpm-software-management/rpm/commit/d6a86b5e69e46cc283b1e06c92343319beb42e21
Patch
Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TMGXO3W6DHPO62GJ4VVF5DEUX5DRUR5K/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VHRPNBCRPDJHHQE3MBPSZK4H7X2IM7AC/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YILPBTPSBRYL4POBI3F4YUSVPSOQNJBY/
https://security.gentoo.org/glsa/202107-43
Third Party Advisory
https://www.starwindsoftware.com/security/sw-20220805-0002/
Third Party Advisory