CVE Vulnerabilities

CVE-2021-3445

Improper Verification of Cryptographic Signature

Published: May 19, 2021 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
5.1 MEDIUM
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
6.4 MODERATE
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

A flaw was found in libdnfs signature verification functionality in versions before 0.60.1. This flaw allows an attacker to achieve code execution if they can alter the header information of an RPM package and then trick a user or system into installing it. The highest risk of this vulnerability is to confidentiality, integrity, as well as system availability.

Weakness

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Affected Software

NameVendorStart VersionEnd Version
LibdnfRpm*0.60.1 (excluding)
Red Hat Enterprise Linux 8RedHatdnf-plugins-core-0:4.0.21-3.el8*
Red Hat Enterprise Linux 8RedHatlibdnf-0:4.7.0-4.el8*
LibdnfUbuntuesm-apps/jammy*
LibdnfUbuntuhirsute*
LibdnfUbuntuimpish*
LibdnfUbuntujammy*
LibdnfUbuntukinetic*
LibdnfUbuntulunar*
LibdnfUbuntumantic*
LibdnfUbuntutrusty*

References