CVE-2021-20271
published 2021-03-26CVE-2021-20271: A flaw was found in RPM's signature check functionality when reading a package file. This flaw allows an attacker who can convince a victim to install a…
PriorityP430high7CVSS 3.1
AVLACHPRNUIRSUCHIHAH
EPSS
0.83%
53.4th percentile
A flaw was found in RPM's signature check functionality when reading a package file. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package, whose signature header was modified, to cause RPM database corruption and execute code. The highest threat from this vulnerability is to data integrity, confidentiality, and system availability.
Affected
36 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | rpm | < rpm 4.16.1.2+dfsg1-1 (bookworm) | rpm 4.16.1.2+dfsg1-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | python-rpm-4.14.2-11.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm | — | — |
| msrc | python-rpm-4.14.2-11.cm1.x86_64.rpm_on_cbl_mariner_1.0_x64 | — | — |
| msrc | python3-rpm-4.14.2-11.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm | — | — |
| msrc | python3-rpm-4.14.2-11.cm1.x86_64.rpm_on_cbl_mariner_1.0_x64 | — | — |
| msrc | rpm-4.14.2-11.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm | — | — |
| msrc | rpm-4.14.2-11.cm1.x86_64.rpm_on_cbl_mariner_1.0_x64 | — | — |
| msrc | rpm-build-4.14.2-11.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm | — | — |
| msrc | rpm-build-4.14.2-11.cm1.x86_64.rpm_on_cbl_mariner_1.0_x64 | — | — |
| msrc | rpm-build-libs-4.14.2-11.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm | — | — |
| msrc | rpm-build-libs-4.14.2-11.cm1.x86_64.rpm_on_cbl_mariner_1.0_x64 | — | — |
| msrc | rpm-debuginfo-4.14.2-11.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm | — | — |
| msrc | rpm-debuginfo-4.14.2-11.cm1.x86_64.rpm_on_cbl_mariner_1.0_x64 | — | — |
| msrc | rpm-devel-4.14.2-11.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm | — | — |
| msrc | rpm-devel-4.14.2-11.cm1.x86_64.rpm_on_cbl_mariner_1.0_x64 | — | — |
| msrc | rpm-lang-4.14.2-11.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm | — | — |
| msrc | rpm-lang-4.14.2-11.cm1.x86_64.rpm_on_cbl_mariner_1.0_x64 | — | — |
| msrc | rpm-libs-4.14.2-11.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm | — | — |
| msrc | rpm-libs-4.14.2-11.cm1.x86_64.rpm_on_cbl_mariner_1.0_x64 | — | — |
| redhat | enterprise_linux | — | — |
| rpm | rpm | — | — |
| rpm | rpm | — | — |
CVSS provenance
nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.05.1MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
osv7.0HIGH
vendor_debian7.0HIGH
vendor_msrc7.0HIGH
vendor_redhat7.0HIGH
vendor_ubuntu4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
RPM Package Manager vulnerabilities
vendor_ubuntu·2022-07-21·CVSS 4.9
CVE-2021-20266 [MEDIUM] RPM Package Manager vulnerabilities
Title: RPM Package Manager vulnerabilities
Summary: Several security issues were fixed in RPM Package Manager.
Demi M. Obenour discovered that RPM Package Manager incorrectly handled
certain files. An attacker could possibly use this issue to corrupt the
database and cause a denial of service. (CVE-2021-3421, CVE-2021-20271)
Demi M. Obenour discovered that RPM Package Manager incorrectly handled
memory when processing certain data from the database. An attacker could
possibly use this issue to cause a denial of service. This issue only
affects Ubuntu 18.04 ESM and Ubuntu 20.04 ESM. (CVE-2021-20266)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
rpm: Signature checks bypass via corrupted rpm package
vendor_redhat·2021-03-11·CVSS 7.0
CVE-2021-20271 [HIGH] CWE-345 rpm: Signature checks bypass via corrupted rpm package
rpm: Signature checks bypass via corrupted rpm package
A flaw was found in RPM's signature check functionality when reading a package file. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package, whose signature header was modified, to cause RPM database corruption and execute code. The highest threat from this vulnerability is to data integrity, confidentiality, and system availability.
A flaw was found in RPM's signature check functionality when reading a package file. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package, whose signature header was modified, to cause RPM database corruption and execute code. The highest threat from this vulnerability is to data integrity, confidentiality, and system a
Microsoft
A flaw was found in RPM's signature check functionality when reading a package file. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package whose signature he
vendor_msrc·2021-03-09·CVSS 7.0
CVE-2021-20271 [HIGH] CWE-345 A flaw was found in RPM's signature check functionality when reading a package file. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package whose signature he
A flaw was found in RPM's signature check functionality when reading a package file. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package whose signature header was modified to cause RPM database corruption and execute code. The highest threat from this vulnerability is to data integrity confidentiality and system availability.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in thi
Debian
CVE-2021-20271: rpm - A flaw was found in RPM's signature check functionality when reading a package f...
vendor_debian·2021·CVSS 7.0
CVE-2021-20271 [HIGH] CVE-2021-20271: rpm - A flaw was found in RPM's signature check functionality when reading a package f...
A flaw was found in RPM's signature check functionality when reading a package file. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package, whose signature header was modified, to cause RPM database corruption and execute code. The highest threat from this vulnerability is to data integrity, confidentiality, and system availability.
Scope: local
bookworm: resolved (fixed in 4.16.1.2+dfsg1-1)
bullseye: resolved (fixed in 4.16.1.2+dfsg1-1)
forky: resolved (fixed in 4.16.1.2+dfsg1-1)
sid: resolved (fixed in 4.16.1.2+dfsg1-1)
trixie: resolved (fixed in 4.16.1.2+dfsg1-1)
OSV
rpm vulnerabilities
osv·2022-07-21·CVSS 4.9
CVE-2021-3421 [MEDIUM] rpm vulnerabilities
rpm vulnerabilities
Demi M. Obenour discovered that RPM Package Manager incorrectly handled
certain files. An attacker could possibly use this issue to corrupt the
database and cause a denial of service. (CVE-2021-3421, CVE-2021-20271)
Demi M. Obenour discovered that RPM Package Manager incorrectly handled
memory when processing certain data from the database. An attacker could
possibly use this issue to cause a denial of service. This issue only
affects Ubuntu 18.04 ESM and Ubuntu 20.04 ESM. (CVE-2021-20266)
GHSA
GHSA-77pm-gxx7-5c5f: A flaw was found in RPM's signature check functionality when reading a package file
ghsa_unreviewed·2022-05-24
CVE-2021-20271 [HIGH] CWE-345 GHSA-77pm-gxx7-5c5f: A flaw was found in RPM's signature check functionality when reading a package file
A flaw was found in RPM's signature check functionality when reading a package file. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package, whose signature header was modified, to cause RPM database corruption and execute code. The highest threat from this vulnerability is to data integrity, confidentiality, and system availability.
OSV
CVE-2021-20271: A flaw was found in RPM's signature check functionality when reading a package file
osv·2021-03-26·CVSS 7.0
CVE-2021-20271 [HIGH] CVE-2021-20271: A flaw was found in RPM's signature check functionality when reading a package file
A flaw was found in RPM's signature check functionality when reading a package file. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package, whose signature header was modified, to cause RPM database corruption and execute code. The highest threat from this vulnerability is to data integrity, confidentiality, and system availability.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=1934125https://github.com/rpm-software-management/rpm/commit/d6a86b5e69e46cc283b1e06c92343319beb42e21https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TMGXO3W6DHPO62GJ4VVF5DEUX5DRUR5K/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VHRPNBCRPDJHHQE3MBPSZK4H7X2IM7AC/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YILPBTPSBRYL4POBI3F4YUSVPSOQNJBY/https://security.gentoo.org/glsa/202107-43https://www.starwindsoftware.com/security/sw-20220805-0002/https://bugzilla.redhat.com/show_bug.cgi?id=1934125https://github.com/rpm-software-management/rpm/commit/d6a86b5e69e46cc283b1e06c92343319beb42e21https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TMGXO3W6DHPO62GJ4VVF5DEUX5DRUR5K/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VHRPNBCRPDJHHQE3MBPSZK4H7X2IM7AC/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YILPBTPSBRYL4POBI3F4YUSVPSOQNJBY/https://security.gentoo.org/glsa/202107-43https://www.starwindsoftware.com/security/sw-20220805-0002/
2021-03-26
Published