CVE Vulnerabilities

CVE-2021-3445

Improper Verification of Cryptographic Signature

Published: May 19, 2021 | Modified: Nov 07, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
5.1 MEDIUM
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
6.4 MODERATE
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM

A flaw was found in libdnfs signature verification functionality in versions before 0.60.1. This flaw allows an attacker to achieve code execution if they can alter the header information of an RPM package and then trick a user or system into installing it. The highest risk of this vulnerability is to confidentiality, integrity, as well as system availability.

Weakness

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Affected Software

Name Vendor Start Version End Version
Libdnf Rpm * 0.60.1 (excluding)
Libdnf Ubuntu devel *
Libdnf Ubuntu esm-apps/jammy *
Libdnf Ubuntu esm-apps/noble *
Libdnf Ubuntu hirsute *
Libdnf Ubuntu impish *
Libdnf Ubuntu jammy *
Libdnf Ubuntu kinetic *
Libdnf Ubuntu lunar *
Libdnf Ubuntu mantic *
Libdnf Ubuntu noble *
Libdnf Ubuntu trusty *
Red Hat Enterprise Linux 8 RedHat dnf-0:4.7.0-4.el8 *
Red Hat Enterprise Linux 8 RedHat dnf-plugins-core-0:4.0.21-3.el8 *
Red Hat Enterprise Linux 8 RedHat libdnf-0:0.63.0-3.el8 *

References