Oval Definition:oval:com.redhat.rhsa:def:20214464
Revision Date:2021-11-09Version:635
Title:RHSA-2021:4464: dnf security and bug fix update (Moderate)
Description:dnf is a package manager that allows users to manage packages on their systems. It supports RPMs, modules and comps groups & environments.

Security Fix(es):

  • libdnf: Signature verification bypass via signature placed in the main RPM header (CVE-2021-3445)

    For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

    Additional Changes:

    For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.5 Release Notes linked from the References section.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2021-3445
    RHSA-2021:4464
    Platform(s):Red Hat Enterprise Linux 8
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 8 is installed
  • OR Red Hat CoreOS 4 is installed
  • AND
  • libdnf is earlier than 0:0.63.0-3.el8
  • AND libdnf is signed with Red Hat redhatrelease2 key
  • libdnf-devel is earlier than 0:0.63.0-3.el8
  • AND libdnf-devel is signed with Red Hat redhatrelease2 key
  • python3-hawkey is earlier than 0:0.63.0-3.el8
  • AND python3-hawkey is signed with Red Hat redhatrelease2 key
  • python3-libdnf is earlier than 0:0.63.0-3.el8
  • AND python3-libdnf is signed with Red Hat redhatrelease2 key
  • dnf-plugins-core is earlier than 0:4.0.21-3.el8
  • AND dnf-plugins-core is signed with Red Hat redhatrelease2 key
  • python3-dnf-plugin-post-transaction-actions is earlier than 0:4.0.21-3.el8
  • AND python3-dnf-plugin-post-transaction-actions is signed with Red Hat redhatrelease2 key
  • python3-dnf-plugin-versionlock is earlier than 0:4.0.21-3.el8
  • AND python3-dnf-plugin-versionlock is signed with Red Hat redhatrelease2 key
  • python3-dnf-plugins-core is earlier than 0:4.0.21-3.el8
  • AND python3-dnf-plugins-core is signed with Red Hat redhatrelease2 key
  • yum-utils is earlier than 0:4.0.21-3.el8
  • AND yum-utils is signed with Red Hat redhatrelease2 key
  • dnf is earlier than 0:4.7.0-4.el8
  • AND dnf is signed with Red Hat redhatrelease2 key
  • dnf-automatic is earlier than 0:4.7.0-4.el8
  • AND dnf-automatic is signed with Red Hat redhatrelease2 key
  • dnf-data is earlier than 0:4.7.0-4.el8
  • AND dnf-data is signed with Red Hat redhatrelease2 key
  • python3-dnf is earlier than 0:4.7.0-4.el8
  • AND python3-dnf is signed with Red Hat redhatrelease2 key
  • yum is earlier than 0:4.7.0-4.el8
  • AND yum is signed with Red Hat redhatrelease2 key
  • BACK