Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2021:4489

Опубликовано: 09 нояб. 2021
Источник: rocky
Оценка: Low

Описание

Low: rpm security, bug fix, and enhancement update

The RPM Package Manager (RPM) is a command-line driven package management system capable of installing, uninstalling, verifying, querying, and updating software packages.

Security Fix(es):

  • rpm: missing length checks in hdrblobInit() (CVE-2021-20266)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Rocky Linux 8.5 Release Notes linked from the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
python3-rpmx86_6419.el8python3-rpm-4.14.3-19.el8.x86_64.rpm
rpmx86_6419.el8rpm-4.14.3-19.el8.x86_64.rpm
rpm-apidocsnoarch19.el8rpm-apidocs-4.14.3-19.el8.noarch.rpm
rpm-apidocsnoarch19.el8rpm-apidocs-4.14.3-19.el8.noarch.rpm
rpm-build-libsi68619.el8rpm-build-libs-4.14.3-19.el8.i686.rpm
rpm-build-libsx86_6419.el8rpm-build-libs-4.14.3-19.el8.x86_64.rpm
rpm-cronnoarch19.el8rpm-cron-4.14.3-19.el8.noarch.rpm
rpm-cronnoarch19.el8rpm-cron-4.14.3-19.el8.noarch.rpm
rpm-develi68619.el8rpm-devel-4.14.3-19.el8.i686.rpm
rpm-develx86_6419.el8rpm-devel-4.14.3-19.el8.x86_64.rpm

Показывать по

Связанные CVE

Связанные уязвимости

CVSS3: 4.9
ubuntu
почти 5 лет назад

A flaw was found in RPM's hdrblobInit() in lib/header.c. This flaw allows an attacker who can modify the rpmdb to cause an out-of-bounds read. The highest threat from this vulnerability is to system availability.

CVSS3: 3.1
redhat
почти 5 лет назад

A flaw was found in RPM's hdrblobInit() in lib/header.c. This flaw allows an attacker who can modify the rpmdb to cause an out-of-bounds read. The highest threat from this vulnerability is to system availability.

CVSS3: 4.9
nvd
почти 5 лет назад

A flaw was found in RPM's hdrblobInit() in lib/header.c. This flaw allows an attacker who can modify the rpmdb to cause an out-of-bounds read. The highest threat from this vulnerability is to system availability.

CVSS3: 4.9
msrc
больше 4 лет назад

Описание отсутствует

CVSS3: 4.9
debian
почти 5 лет назад

A flaw was found in RPM's hdrblobInit() in lib/header.c. This flaw all ...