Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-20266

Опубликовано: 11 мар. 2021
Источник: redhat
CVSS3: 3.1

Описание

A flaw was found in RPM's hdrblobInit() in lib/header.c. This flaw allows an attacker who can modify the rpmdb to cause an out-of-bounds read. The highest threat from this vulnerability is to system availability.

A flaw was found in RPM’s hdrblobInit() in lib/header.c. This flaw allows an attacker who can modify the rpmdb to cause an out-of-bounds read. The highest threat from this vulnerability is to system availability.

Отчет

In order to exploit this flaw with rpm tooling as shipped in Red Hat Enterprise Linux, an attacker would need to already have root access to modify the rpm database.

Меры по смягчению последствий

If using the headerCheck() and headerImport() APIs in your software, do not run them on headers from untrusted sources.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6rpmOut of support scope
Red Hat Enterprise Linux 7rpmOut of support scope
Red Hat Enterprise Linux 9rpmNot affected
Red Hat Enterprise Linux 8rpmFixedRHSA-2021:448909.11.2021
Red Hat Enterprise Linux 8rpmFixedRHSA-2021:448909.11.2021

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1927741rpm: missing length checks in hdrblobInit()

3.1 Low

CVSS3

Связанные уязвимости

CVSS3: 4.9
ubuntu
почти 5 лет назад

A flaw was found in RPM's hdrblobInit() in lib/header.c. This flaw allows an attacker who can modify the rpmdb to cause an out-of-bounds read. The highest threat from this vulnerability is to system availability.

CVSS3: 4.9
nvd
почти 5 лет назад

A flaw was found in RPM's hdrblobInit() in lib/header.c. This flaw allows an attacker who can modify the rpmdb to cause an out-of-bounds read. The highest threat from this vulnerability is to system availability.

CVSS3: 4.9
msrc
больше 4 лет назад

Описание отсутствует

CVSS3: 4.9
debian
почти 5 лет назад

A flaw was found in RPM's hdrblobInit() in lib/header.c. This flaw all ...

rocky
около 4 лет назад

Low: rpm security, bug fix, and enhancement update

3.1 Low

CVSS3