PT-2021-6079 · Rpm+8 · Rpm+8

Demi Marie Obenour

·

Published

2021-03-11

·

Updated

2023-02-12

·

CVE-2021-20271

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions RPM (affected versions not specified)
Description The issue is related to insufficient authentication of data in the RPM software's signature check functionality. This allows an attacker to potentially corrupt the RPM database and execute code by convincing a victim to install a modified package. The highest threat from this issue is to data integrity, confidentiality, and system availability.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-00716
CESA-2021_2574
CESA-2021_4785
CVE-2021-20271
MGASA-2021-0167
OESA-2021-1163
OPENSUSE-SU-2021:1366-1
OPENSUSE-SU-2021:2682-1
OPENSUSE-SU-2021:2685-1
OPENSUSE-SU-2021_1366-1
OPENSUSE-SU-2021_2682-1
OPENSUSE-SU-2021_2685-1
RHSA-2021:2574
RHSA-2021:2791
RHSA-2021:4771
RHSA-2021:4785
RHSA-2021:4975
RHSA-2021_2574
RHSA-2021_4785
RLSA-2021:2574
SUSE-SU-2021:2682-1
SUSE-SU-2021:3444-1
SUSE-SU-2022:3939-1
USN-5273-1

Affected Products

Astra Linux
Centos
Ibm Aix
Linuxmint
Rpm
Red Hat
Rocky Linux
Suse
Ubuntu