CVE Vulnerabilities

CVE-2021-3445

Improper Verification of Cryptographic Signature

Published: May 19, 2021 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
5.1 MEDIUM
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
6.4 MODERATE
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM

A flaw was found in libdnfs signature verification functionality in versions before 0.60.1. This flaw allows an attacker to achieve code execution if they can alter the header information of an RPM package and then trick a user or system into installing it. The highest risk of this vulnerability is to confidentiality, integrity, as well as system availability.

Weakness

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Affected Software

Name Vendor Start Version End Version
Libdnf Rpm * 0.60.1 (excluding)
Red Hat Enterprise Linux 8 RedHat dnf-0:4.7.0-4.el8 *
Red Hat Enterprise Linux 8 RedHat dnf-plugins-core-0:4.0.21-3.el8 *
Red Hat Enterprise Linux 8 RedHat libdnf-0:0.63.0-3.el8 *
Libdnf Ubuntu hirsute *
Libdnf Ubuntu impish *
Libdnf Ubuntu jammy *
Libdnf Ubuntu kinetic *
Libdnf Ubuntu lunar *
Libdnf Ubuntu mantic *
Libdnf Ubuntu trusty *

References