Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-20266

Опубликовано: 30 апр. 2021
Источник: nvd
CVSS3: 4.9
CVSS2: 4
EPSS Низкий

Описание

A flaw was found in RPM's hdrblobInit() in lib/header.c. This flaw allows an attacker who can modify the rpmdb to cause an out-of-bounds read. The highest threat from this vulnerability is to system availability.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:rpm:rpm:*:*:*:*:*:*:*:*
Версия до 4.16.1.3 (исключая)
Конфигурация 2

Одно из

cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*

EPSS

Процентиль: 20%
0.00063
Низкий

4.9 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 4.9
ubuntu
почти 5 лет назад

A flaw was found in RPM's hdrblobInit() in lib/header.c. This flaw allows an attacker who can modify the rpmdb to cause an out-of-bounds read. The highest threat from this vulnerability is to system availability.

CVSS3: 3.1
redhat
почти 5 лет назад

A flaw was found in RPM's hdrblobInit() in lib/header.c. This flaw allows an attacker who can modify the rpmdb to cause an out-of-bounds read. The highest threat from this vulnerability is to system availability.

CVSS3: 4.9
msrc
больше 4 лет назад

Описание отсутствует

CVSS3: 4.9
debian
почти 5 лет назад

A flaw was found in RPM's hdrblobInit() in lib/header.c. This flaw all ...

rocky
около 4 лет назад

Low: rpm security, bug fix, and enhancement update

EPSS

Процентиль: 20%
0.00063
Низкий

4.9 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-125