CVE Vulnerabilities

CVE-2021-20271

Insufficient Verification of Data Authenticity

Published: Mar 26, 2021 | Modified: Nov 21, 2024
CVSS 3.x
7
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
5.1 MEDIUM
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
6.7 MODERATE
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

A flaw was found in RPMs signature check functionality when reading a package file. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package, whose signature header was modified, to cause RPM database corruption and execute code. The highest threat from this vulnerability is to data integrity, confidentiality, and system availability.

Weakness

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Affected Software

NameVendorStart VersionEnd Version
RpmRpm4.15.0 (including)4.15.1.3 (excluding)
RpmRpm4.16.0 (including)4.16.1.3 (excluding)
RpmRpm4.15.0-alpha (including)4.15.0-alpha (including)
RpmRpm4.15.0-beta1 (including)4.15.0-beta1 (including)
RpmRpm4.15.0-rc1 (including)4.15.0-rc1 (including)
RpmRpm4.16.0-alpha (including)4.16.0-alpha (including)
RpmRpm4.16.0-beta2 (including)4.16.0-beta2 (including)
RpmRpm4.16.0-beta3 (including)4.16.0-beta3 (including)
RpmRpm4.16.0-rc1 (including)4.16.0-rc1 (including)
Red Hat Enterprise Linux 7RedHatrpm-0:4.11.3-48.el7_9*
Red Hat Enterprise Linux 7.6 Advanced Update Support(Disable again in 2026 - SPRHEL-7118)RedHatrpm-0:4.11.3-35.el7_6.2*
Red Hat Enterprise Linux 7.6 Telco Extended Update SupportRedHatrpm-0:4.11.3-35.el7_6.2*
Red Hat Enterprise Linux 7.6 Update Services for SAP SolutionsRedHatrpm-0:4.11.3-35.el7_6.2*
Red Hat Enterprise Linux 7.7 Advanced Update SupportRedHatrpm-0:4.11.3-40.el7_7.1*
Red Hat Enterprise Linux 7.7 Telco Extended Update SupportRedHatrpm-0:4.11.3-40.el7_7.1*
Red Hat Enterprise Linux 7.7 Update Services for SAP SolutionsRedHatrpm-0:4.11.3-40.el7_7.1*
Red Hat Enterprise Linux 8RedHatrpm-0:4.14.3-14.el8_4*
Red Hat Enterprise Linux 8RedHatrpm-0:4.14.3-14.el8_4*
Red Hat Enterprise Linux 8.2 Extended Update SupportRedHatrpm-0:4.14.2-38.el8_2*
Red Hat Migration Toolkit for Containers 1.4RedHatrhmtc/openshift-migration-controller-rhel8:v1.4.6-4*
Red Hat Migration Toolkit for Containers 1.4RedHatrhmtc/openshift-migration-log-reader-rhel8:v1.4.6-4*
Red Hat Migration Toolkit for Containers 1.4RedHatrhmtc/openshift-migration-must-gather-rhel8:v1.4.6-4*
Red Hat Migration Toolkit for Containers 1.4RedHatrhmtc/openshift-migration-operator-bundle:v1.4.6-5*
Red Hat Migration Toolkit for Containers 1.4RedHatrhmtc/openshift-migration-registry-rhel8:v1.4.6-4*
Red Hat Migration Toolkit for Containers 1.4RedHatrhmtc/openshift-migration-rsync-transfer-rhel8:v1.4.6-4*
Red Hat Migration Toolkit for Containers 1.4RedHatrhmtc/openshift-migration-ui-rhel8:v1.4.6-4*
Red Hat Migration Toolkit for Containers 1.4RedHatrhmtc/openshift-migration-velero-plugin-for-aws-rhel8:v1.4.6-4*
Red Hat Migration Toolkit for Containers 1.4RedHatrhmtc/openshift-migration-velero-plugin-for-gcp-rhel8:v1.4.6-3*
Red Hat Migration Toolkit for Containers 1.4RedHatrhmtc/openshift-migration-velero-plugin-for-microsoft-azure-rhel8:v1.4.6-4*
Red Hat Migration Toolkit for Containers 1.4RedHatrhmtc/openshift-migration-velero-restic-restore-helper-rhel8:v1.4.6-5*
Red Hat Migration Toolkit for Containers 1.4RedHatrhmtc/openshift-migration-velero-rhel8:v1.4.6-5*
Red Hat Migration Toolkit for Containers 1.4RedHatrhmtc/openshift-velero-plugin-rhel8:v1.4.6-4*
RpmUbuntubionic*
RpmUbuntuesm-apps/bionic*
RpmUbuntuesm-apps/focal*
RpmUbuntuesm-apps/xenial*
RpmUbuntuesm-infra-legacy/trusty*
RpmUbuntufocal*
RpmUbuntugroovy*
RpmUbuntuhirsute*
RpmUbuntuimpish*
RpmUbuntuprecise/esm*
RpmUbuntutrusty*
RpmUbuntutrusty/esm*
RpmUbuntuupstream*
RpmUbuntuxenial*

References