6.4

CVE-2021-35937

Exploit
A race condition vulnerability was found in rpm. A local unprivileged user could use this flaw to bypass the checks that were introduced in response to CVE-2017-7500 and CVE-2017-7501, potentially gaining root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Rpm ≫ Rpm Version < 4.18.0
Redhat ≫ Enterprise Linux Version 6.0
Redhat ≫ Enterprise Linux Version 7.0
Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Enterprise Linux Version 9.0
Fedoraproject ≫ Fedora Version 34
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.31% 0.238
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.4 0.5 5.9
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition

The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.

CWE-59 Improper Link Resolution Before File Access ('Link Following')

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

https://security.gentoo.org/glsa/202210-22
Third Party Advisory
https://access.redhat.com/security/cve/CVE-2021-35937
Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1964125
Patch
Vendor Advisory
Issue Tracking
https://rpm.org/wiki/Releases/4.18.0
Release Notes
https://www.usenix.org/legacy/event/sec05/tech/full_papers/borisov/borisov.pdf
Third Party Advisory
Exploit
Technical Description