CVE-2021-35939
- EPSS 0.15%
- Published 26.08.2022 16:15:08
- Last modified 21.11.2024 06:12:47
It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to be created. A local unprivileged user who owns another ancestor directory could potentially use this ...
CVE-2021-35938
- EPSS 0.11%
- Published 25.08.2022 20:15:09
- Last modified 21.11.2024 06:12:47
A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical f...
CVE-2021-35937
- EPSS 0.01%
- Published 25.08.2022 20:15:09
- Last modified 21.11.2024 06:12:47
A race condition vulnerability was found in rpm. A local unprivileged user could use this flaw to bypass the checks that were introduced in response to CVE-2017-7500 and CVE-2017-7501, potentially gaining root privileges. The highest threat from this...
CVE-2021-3521
- EPSS 0.02%
- Published 22.08.2022 15:15:13
- Last modified 21.11.2024 06:21:45
There is a flaw in RPM's signature functionality. OpenPGP subkeys are associated with a primary key via a "binding signature." RPM does not check the binding signature of subkeys prior to importing them. If an attacker is able to add or socially engi...
CVE-2021-3421
- EPSS 0.05%
- Published 19.05.2021 14:15:07
- Last modified 21.11.2024 06:21:27
A flaw was found in the RPM package in the read functionality. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package or compromise an RPM repository, to cause RPM database corruption. The highest threat from...
CVE-2021-20266
- EPSS 0.07%
- Published 30.04.2021 12:15:07
- Last modified 21.11.2024 05:46:14
A flaw was found in RPM's hdrblobInit() in lib/header.c. This flaw allows an attacker who can modify the rpmdb to cause an out-of-bounds read. The highest threat from this vulnerability is to system availability.
- EPSS 0.2%
- Published 26.03.2021 17:15:13
- Last modified 21.11.2024 05:46:15
A flaw was found in RPM's signature check functionality when reading a package file. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package, whose signature header was modified, to cause RPM database corrupti...
CVE-2017-7500
- EPSS 0.05%
- Published 13.08.2018 17:29:00
- Last modified 21.11.2024 03:32:01
It was found that rpm did not properly handle RPM installations when a destination path was a symbolic link to a directory, possibly changing ownership and permissions of an arbitrary directory, and RPM files being placed in an arbitrary destination....
CVE-2017-7501
- EPSS 0.05%
- Published 22.11.2017 22:29:00
- Last modified 20.04.2025 01:37:25
It was found that versions of rpm before 4.13.0.2 use temporary files with predictable names when installing an RPM. An attacker with ability to write in a directory where files will be installed could create symbolic links to an arbitrary location a...
- EPSS 11.8%
- Published 16.12.2014 18:59:06
- Last modified 12.04.2025 10:46:40
Integer overflow in RPM 4.12 and earlier allows remote attackers to execute arbitrary code via a crafted CPIO header in the payload section of an RPM file, which triggers a stack-based buffer overflow.