HIGH 7.0 Microsoft
CVE-2021-20271
A flaw was found in RPM's signature check functionality when reading a package file. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package whose signature header was modified to cause RPM database corruption and execute code. The highest threat from this vulnerability is to data integrity confidentiality and system availability.
Microsoft Security Update 2021-Mar: A flaw was found in RPM's signature check functionality when reading a package file. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package whose signature header was modified to cause RPM database corruption and execute code. The highest threat from this vulnerability is to data integrity confidentiality and system availability.
Affected Products
- rpm-4.14.2-11.cm1.x86_64.rpm on CBL Mariner 1.0 x64
- rpm-devel-4.14.2-11.cm1.x86_64.rpm on CBL Mariner 1.0 x64
- rpm-libs-4.14.2-11.cm1.x86_64.rpm on CBL Mariner 1.0 x64
- rpm-build-libs-4.14.2-11.cm1.x86_64.rpm on CBL Mariner 1.0 x64
- rpm-build-4.14.2-11.cm1.x86_64.rpm on CBL Mariner 1.0 x64
- rpm-lang-4.14.2-11.cm1.x86_64.rpm on CBL Mariner 1.0 x64
- python-rpm-4.14.2-11.cm1.x86_64.rpm on CBL Mariner 1.0 x64
- python3-rpm-4.14.2-11.cm1.x86_64.rpm on CBL Mariner 1.0 x64
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-20271
- https://nvd.nist.gov/vuln/detail/CVE-2021-20271
This high severity vulnerability with a CVSS score of 7.0 was published on 2021-03-09 via Microsoft. Affected: rpm-4.14.2-11.cm1.x86_64.rpm on CBL Mariner 1.0 x64, rpm-devel-4.14.2-11.cm1.x86_64.rpm on CBL Mariner 1.0 x64, rpm-libs-4.14.2-11.cm1.x86_64.rpm on CBL Mariner 1.0 x64 and 5 more.
vulnfeed aggregates 11644 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.