Oval Definition:oval:org.opensuse.security:def:64740
Revision Date:2021-08-12Version:1
Title:Security update for rpm (Important)
Description:

This update for rpm fixes the following issues:

- Changed default package verification level to 'none' to be compatible to rpm-4.14.1 - Made illegal obsoletes a warning - Fixed a potential access of freed mem in ndb's glue code (bsc#1179416) - Added support for enforcing signature policy and payload verification step to transactions (jsc#SLE-17817) - Added :humansi and :hmaniec query formatters for human readable output - Added query selectors for whatobsoletes and whatconflicts - Added support for sorting caret higher than base version - rpm does no longer require the signature header to be in a contiguous region when signing (bsc#1181805)

Security fixes:

- CVE-2021-3421: A flaw was found in the RPM package in the read functionality. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package or compromise an RPM repository, to cause RPM database corruption. The highest threat from this vulnerability is to data integrity (bsc#1183543)

- CVE-2021-20271: A flaw was found in RPM's signature check functionality when reading a package file. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package, whose signature header was modified, to cause RPM database corruption and execute code. The highest threat from this vulnerability is to data integrity, confidentiality, and system availability (bsc#1183545)

- CVE-2021-20266: A flaw was found in RPM's hdrblobInit() in lib/header.c. This flaw allows an attacker who can modify the rpmdb to cause an out-of-bounds read. The highest threat from this vulnerability is to system availability.
Family:unixClass:patch
Status:Reference(s):1024288
1024291
1027519
1084631
1086186
1086227
1086228
1090519
1090840
1106878
1107592
1107594
1108404
1115758
1115774
1115795
1136936
1154971
1156196
1168669
1169039
1169040
1172205
1173032
1173274
1173376
1173377
1173378
1173380
1173538
1176312
1176535
1179416
1181805
1183543
1183545
CVE-2014-0222
CVE-2014-0223
CVE-2014-3461
CVE-2014-3640
CVE-2014-7840
CVE-2014-8106
CVE-2015-1779
CVE-2015-3209
CVE-2015-3456
CVE-2015-4037
CVE-2015-5154
CVE-2015-5225
CVE-2015-5278
CVE-2015-5279
CVE-2015-5745
CVE-2015-6815
CVE-2015-6855
CVE-2015-7295
CVE-2015-7512
CVE-2015-7549
CVE-2015-8345
CVE-2015-8504
CVE-2015-8558
CVE-2015-8567
CVE-2015-8568
CVE-2015-8613
CVE-2015-8619
CVE-2015-8743
CVE-2015-8744
CVE-2015-8745
CVE-2016-10028
CVE-2016-10155
CVE-2016-1568
CVE-2016-1714
CVE-2016-1922
CVE-2016-1981
CVE-2016-2198
CVE-2016-3710
CVE-2016-3712
CVE-2016-4002
CVE-2016-4020
CVE-2016-4439
CVE-2016-4441
CVE-2016-4453
CVE-2016-4454
CVE-2016-4952
CVE-2016-4964
CVE-2016-5105
CVE-2016-5106
CVE-2016-5107
CVE-2016-5126
CVE-2016-5238
CVE-2016-5337
CVE-2016-5338
CVE-2016-5403
CVE-2016-6351
CVE-2016-6490
CVE-2016-6833
CVE-2016-6836
CVE-2016-6888
CVE-2016-7116
CVE-2016-7155
CVE-2016-7156
CVE-2016-7157
CVE-2016-7161
CVE-2016-7170
CVE-2016-7421
CVE-2016-7422
CVE-2016-7423
CVE-2016-7466
CVE-2016-7907
CVE-2016-7908
CVE-2016-7909
CVE-2016-7994
CVE-2016-7995
CVE-2016-8576
CVE-2016-8577
CVE-2016-8578
CVE-2016-8667
CVE-2016-8668
CVE-2016-8669
CVE-2016-8909
CVE-2016-8910
CVE-2016-9101
CVE-2016-9102
CVE-2016-9103
CVE-2016-9104
CVE-2016-9105
CVE-2016-9106
CVE-2016-9381
CVE-2016-9602
CVE-2016-9776
CVE-2016-9845
CVE-2016-9846
CVE-2016-9907
CVE-2016-9908
CVE-2016-9911
CVE-2016-9912
CVE-2016-9913
CVE-2016-9921
CVE-2016-9922
CVE-2016-9923
CVE-2017-10664
CVE-2017-10806
CVE-2017-11334
CVE-2017-11434
CVE-2017-12911
CVE-2017-13672
CVE-2017-13673
CVE-2017-13711
CVE-2017-14167
CVE-2017-15038
CVE-2017-15118
CVE-2017-15119
CVE-2017-15268
CVE-2017-15289
CVE-2017-2579
CVE-2017-2580
CVE-2017-2615
CVE-2017-2620
CVE-2017-2630
CVE-2017-2633
CVE-2017-5525
CVE-2017-5526
CVE-2017-5552
CVE-2017-5578
CVE-2017-5579
CVE-2017-5667
CVE-2017-5715
CVE-2017-5856
CVE-2017-5857
CVE-2017-5898
CVE-2017-5931
CVE-2017-5973
CVE-2017-5987
CVE-2017-6058
CVE-2017-6505
CVE-2017-7471
CVE-2017-7493
CVE-2017-8112
CVE-2017-8309
CVE-2017-8379
CVE-2017-8380
CVE-2017-9503
CVE-2017-9524
CVE-2018-1000667
CVE-2018-10016
CVE-2018-10254
CVE-2018-10316
CVE-2018-10839
CVE-2018-11806
CVE-2018-12126
CVE-2018-12127
CVE-2018-12130
CVE-2018-12617
CVE-2018-15746
CVE-2018-16382
CVE-2018-16517
CVE-2018-16847
CVE-2018-16872
CVE-2018-16999
CVE-2018-17958
CVE-2018-17962
CVE-2018-17963
CVE-2018-18849
CVE-2018-19214
CVE-2018-19215
CVE-2018-19216
CVE-2018-20123
CVE-2018-20124
CVE-2018-20125
CVE-2018-20126
CVE-2018-20191
CVE-2018-20216
CVE-2018-20815
CVE-2018-3639
CVE-2018-7550
CVE-2018-7858
CVE-2018-8881
CVE-2018-8882
CVE-2018-8883
CVE-2019-11091
CVE-2019-18359
CVE-2019-20637
CVE-2019-3812
CVE-2019-6778
CVE-2019-8934
CVE-2019-9824
CVE-2020-0543
CVE-2020-11653
CVE-2020-12402
CVE-2020-14422
CVE-2020-15563
CVE-2020-15565
CVE-2020-15566
CVE-2020-15567
CVE-2020-17482
CVE-2021-20266
CVE-2021-20271
CVE-2021-3421
openSUSE-SU-2020:0522-1
openSUSE-SU-2020:0808-1
openSUSE-SU-2020:0954-1
openSUSE-SU-2020:0955-1
openSUSE-SU-2020:0985-1
openSUSE-SU-2020:1002-1
openSUSE-SU-2020:1556-1
SUSE-SU-2019:1525-1
SUSE-SU-2021:2682-1
Platform(s):openSUSE Leap 15.1
openSUSE Leap 15.2
SUSE Linux Enterprise Desktop 15 SP3
SUSE Linux Enterprise High Performance Computing 15 SP3
SUSE Linux Enterprise Module for Basesystem 15 SP1
SUSE Linux Enterprise Module for Basesystem 15 SP3
SUSE Linux Enterprise Module for Server Applications 15 SP1
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise Server for SAP Applications 15 SP3
SUSE Manager Proxy 4.2
SUSE Manager Server 4.2
Product(s):
Definition Synopsis
  • openSUSE Leap 15.1 is installed
  • AND mp3gain-1.6.2-lp151.3.3 is installed
  • Definition Synopsis
  • openSUSE Leap 15.2 is installed
  • AND python-ipaddress-1.0.18-lp152.4.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Basesystem 15 SP3 is installed
  • AND Package Information
  • python3-rpm-4.14.3-37.2 is installed
  • OR rpm-4.14.3-37.2 is installed
  • OR rpm-32bit-4.14.3-37.2 is installed
  • OR rpm-devel-4.14.3-37.2 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Basesystem 15 SP1 is installed
  • AND Package Information
  • libnetpbm11-10.80.1-3.8 is installed
  • OR netpbm-10.80.1-3.8 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Server Applications 15 SP1 is installed
  • AND Package Information
  • qemu-3.1.0-7 is installed
  • OR qemu-audio-alsa-3.1.0-7 is installed
  • OR qemu-audio-oss-3.1.0-7 is installed
  • OR qemu-audio-pa-3.1.0-7 is installed
  • OR qemu-block-curl-3.1.0-7 is installed
  • OR qemu-block-iscsi-3.1.0-7 is installed
  • OR qemu-block-rbd-3.1.0-7 is installed
  • OR qemu-block-ssh-3.1.0-7 is installed
  • OR qemu-guest-agent-3.1.0-7 is installed
  • OR qemu-ipxe-1.0.0+-7 is installed
  • OR qemu-kvm-3.1.0-7 is installed
  • OR qemu-lang-3.1.0-7 is installed
  • OR qemu-ppc-3.1.0-7 is installed
  • OR qemu-s390-3.1.0-7 is installed
  • OR qemu-seabios-1.12.0-7 is installed
  • OR qemu-sgabios-8-7 is installed
  • OR qemu-ui-curses-3.1.0-7 is installed
  • OR qemu-ui-gtk-3.1.0-7 is installed
  • OR qemu-vgabios-1.12.0-7 is installed
  • OR qemu-x86-3.1.0-7 is installed
  • BACK