PT-2021-6079 · Rpm+8 · Rpm+8
Demi Marie Obenour
·
Published
2021-03-11
·
Updated
2023-02-12
·
CVE-2021-20271
CVSS v3.1
7.0
High
| Vector | AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
RPM (affected versions not specified)
Description
The issue is related to insufficient authentication of data in the RPM software's signature check functionality. This allows an attacker to potentially corrupt the RPM database and execute code by convincing a victim to install a modified package. The highest threat from this issue is to data integrity, confidentiality, and system availability.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Centos
Ibm Aix
Linuxmint
Rpm
Red Hat
Rocky Linux
Suse
Ubuntu