Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-3421

Опубликовано: 11 мар. 2021
Источник: redhat
CVSS3: 4.7
EPSS Низкий

Описание

A flaw was found in the RPM package in the read functionality. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package or compromise an RPM repository, to cause RPM database corruption. The highest threat from this vulnerability is to data integrity. This flaw affects RPM versions before 4.17.0-alpha.

A flaw was found in the RPM package in the read functionality. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package or compromise an RPM repository, to cause RPM database corruption. The highest threat from this vulnerability is to data integrity.

Отчет

To exploit this flaw, an attacker must either compromise an RPM repository or convince an administrator to install an untrusted RPM. It is strongly recommended to only use RPMs from trusted repositories.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6rpmOut of support scope
Red Hat Enterprise Linux 7rpmOut of support scope
Red Hat Enterprise Linux 9rpmNot affected
Red Hat Enterprise Linux 8rpmFixedRHSA-2021:257429.06.2021
Red Hat Enterprise Linux 8rpmFixedRHSA-2021:257429.06.2021
Red Hat Enterprise Linux 8.2 Extended Update SupportrpmFixedRHSA-2021:279120.07.2021

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-347
https://bugzilla.redhat.com/show_bug.cgi?id=1927747rpm: unsigned signature header leads to string injection into an rpm database

EPSS

Процентиль: 15%
0.00048
Низкий

4.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 4 лет назад

A flaw was found in the RPM package in the read functionality. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package or compromise an RPM repository, to cause RPM database corruption. The highest threat from this vulnerability is to data integrity. This flaw affects RPM versions before 4.17.0-alpha.

CVSS3: 5.5
nvd
больше 4 лет назад

A flaw was found in the RPM package in the read functionality. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package or compromise an RPM repository, to cause RPM database corruption. The highest threat from this vulnerability is to data integrity. This flaw affects RPM versions before 4.17.0-alpha.

CVSS3: 5.5
msrc
больше 4 лет назад

A flaw was found in the RPM package in the read functionality. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package or compromise an RPM repository to cause RPM database corruption. The highest threat from this vulnerability is to data integrity. This flaw affects RPM versions before 4.17.0-alpha.

CVSS3: 5.5
debian
больше 4 лет назад

A flaw was found in the RPM package in the read functionality. This fl ...

CVSS3: 5.5
github
больше 3 лет назад

A flaw was found in the RPM package in the read functionality. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package or compromise an RPM repository, to cause RPM database corruption. The highest threat from this vulnerability is to data integrity. This flaw affects RPM versions before 4.17.0-alpha.

EPSS

Процентиль: 15%
0.00048
Низкий

4.7 Medium

CVSS3