Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2024:0647

Опубликовано: 12 фев. 2024
Источник: rocky
Оценка: Moderate

Описание

Moderate: rpm security update

The RPM Package Manager (RPM) is a command-line driven package management system capable of installing, uninstalling, verifying, querying, and updating software packages.

Security Fix(es):

  • rpm: TOCTOU race in checks for unsafe symlinks (CVE-2021-35937)

  • rpm: races with chown/chmod/capabilities calls during installation (CVE-2021-35938)

  • rpm: checks for unsafe symlinks are not performed for intermediary directories (CVE-2021-35939)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
python3-rpmaarch6428.el8_9python3-rpm-4.14.3-28.el8_9.aarch64.rpm
rpmaarch6428.el8_9rpm-4.14.3-28.el8_9.aarch64.rpm
rpm-apidocsnoarch28.el8_9rpm-apidocs-4.14.3-28.el8_9.noarch.rpm
rpm-build-libsaarch6428.el8_9rpm-build-libs-4.14.3-28.el8_9.aarch64.rpm
rpm-cronnoarch28.el8_9rpm-cron-4.14.3-28.el8_9.noarch.rpm
rpm-develaarch6428.el8_9rpm-devel-4.14.3-28.el8_9.aarch64.rpm
rpm-libsaarch6428.el8_9rpm-libs-4.14.3-28.el8_9.aarch64.rpm
rpm-plugin-imaaarch6428.el8_9rpm-plugin-ima-4.14.3-28.el8_9.aarch64.rpm
rpm-plugin-prioresetaarch6428.el8_9rpm-plugin-prioreset-4.14.3-28.el8_9.aarch64.rpm
rpm-plugin-selinuxaarch6428.el8_9rpm-plugin-selinux-4.14.3-28.el8_9.aarch64.rpm

Показывать по

Связанные уязвимости

oracle-oval
больше 1 года назад

ELSA-2024-0647: rpm security update (MODERATE)

oracle-oval
больше 1 года назад

ELSA-2024-0463: rpm security update (MODERATE)

CVSS3: 6.5
redos
больше 1 года назад

Множественные уязвимости rpm

CVSS3: 6.4
ubuntu
почти 3 года назад

A race condition vulnerability was found in rpm. A local unprivileged user could use this flaw to bypass the checks that were introduced in response to CVE-2017-7500 and CVE-2017-7501, potentially gaining root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 6.3
redhat
около 4 лет назад

A race condition vulnerability was found in rpm. A local unprivileged user could use this flaw to bypass the checks that were introduced in response to CVE-2017-7500 and CVE-2017-7501, potentially gaining root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.