Oval Definition:oval:org.opensuse.security:def:68766
Revision Date:2021-08-12Version:1
Title:Security update for rpm (Important)
Description:

This update for rpm fixes the following issues:

- Changed default package verification level to 'none' to be compatible to rpm-4.14.1 - Made illegal obsoletes a warning - Fixed a potential access of freed mem in ndb's glue code (bsc#1179416) - Added support for enforcing signature policy and payload verification step to transactions (jsc#SLE-17817) - Added :humansi and :hmaniec query formatters for human readable output - Added query selectors for whatobsoletes and whatconflicts - Added support for sorting caret higher than base version - rpm does no longer require the signature header to be in a contiguous region when signing (bsc#1181805)

Security fixes:

- CVE-2021-3421: A flaw was found in the RPM package in the read functionality. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package or compromise an RPM repository, to cause RPM database corruption. The highest threat from this vulnerability is to data integrity (bsc#1183543)

- CVE-2021-20271: A flaw was found in RPM's signature check functionality when reading a package file. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package, whose signature header was modified, to cause RPM database corruption and execute code. The highest threat from this vulnerability is to data integrity, confidentiality, and system availability (bsc#1183545)

- CVE-2021-20266: A flaw was found in RPM's hdrblobInit() in lib/header.c. This flaw allows an attacker who can modify the rpmdb to cause an out-of-bounds read. The highest threat from this vulnerability is to system availability.
Family:unixClass:patch
Status:Reference(s):1046299
1046303
1046305
1048942
1050244
1050536
1050545
1051510
1054914
1055117
1055186
1061840
1064802
1065600
1065729
1066129
1071995
1073513
1082555
1082635
1083647
1086323
1087092
1089644
1090631
1091041
1093205
1096254
1097583
1097584
1097585
1097586
1097587
1097588
1098291
1101674
1104967
1109158
1111666
1112178
1113722
1113994
1114279
1117665
1119086
1119461
1119465
1123034
1123080
1127988
1131107
1131304
1133140
1134303
1135642
1135854
1135873
1135966
1135967
1137040
1137069
1137799
1137861
1137865
1137959
1137982
1138190
1138459
1139073
1140090
1140155
1140729
1140845
1140883
1141013
1141600
1142076
1142635
1142667
1143706
1144338
1144375
1144449
1144903
1145099
1146042
1146519
1146540
1146612
1146664
1148133
1148410
1148712
1148868
1149119
1149313
1149446
1149448
1149555
1149651
1149853
1150305
1150381
1150423
1150452
1150457
1150465
1150466
1150846
1150875
1151067
1151192
1151350
1151508
1151610
1151661
1151662
1151667
1151680
1151807
1151891
1151955
1152024
1152025
1152026
1152033
1152161
1152187
1152243
1152325
1152457
1152460
1152466
1152497
1152505
1152506
1152525
1152624
1152665
1152685
1152696
1152697
1152782
1152788
1152790
1152791
1152972
1152974
1152975
1153112
1153158
1153236
1153263
1153476
1153509
1153607
1153646
1153681
1153713
1153717
1153718
1153719
1153811
1153969
1154108
1154124
1154189
1154242
1154268
1154354
1154372
1154521
1154526
1154578
1154601
1154607
1154608
1154610
1154611
1154651
1154737
1154747
1154848
1154858
1154905
1154956
1155021
1155061
1155178
1155179
1155184
1155186
1155671
1155692
1155812
1155817
1155836
1155945
1155982
1156187
1156429
1156466
1156494
1156609
1156700
1156729
1156882
1179416
1181805
1183543
1183545
CVE-2017-18595
CVE-2018-12207
CVE-2019-0154
CVE-2019-0155
CVE-2019-10160
CVE-2019-10220
CVE-2019-11135
CVE-2019-14821
CVE-2019-15291
CVE-2019-15916
CVE-2019-16231
CVE-2019-16232
CVE-2019-16233
CVE-2019-16234
CVE-2019-16995
CVE-2019-17055
CVE-2019-17056
CVE-2019-17133
CVE-2019-17666
CVE-2019-18805
CVE-2019-9506
CVE-2021-20266
CVE-2021-20271
CVE-2021-3421
SUSE-SU-2019:2064-1
SUSE-SU-2019:3295-1
SUSE-SU-2021:2682-1
Platform(s):SUSE Linux Enterprise Desktop 15 SP3
SUSE Linux Enterprise High Performance Computing 15 SP3
SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 SP1
SUSE Linux Enterprise Module for Python 2 15 SP3
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise Server for SAP Applications 15 SP3
SUSE Manager Proxy 4.2
SUSE Manager Server 4.2
Product(s):
Definition Synopsis
  • SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 SP1 is installed
  • AND Package Information
  • libpython2_7-1_0-32bit-2.7.14-7.14 is installed
  • OR python-2.7.14-7.14 is installed
  • OR python-32bit-2.7.14-7.14 is installed
  • OR python-base-2.7.14-7.14 is installed
  • OR python-base-32bit-2.7.14-7.14 is installed
  • OR python-demo-2.7.14-7.14 is installed
  • OR python-doc-2.7.14-7.14 is installed
  • OR python-doc-pdf-2.7.14-7.14 is installed
  • OR python-idle-2.7.14-7.14 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Python 2 15 SP3 is installed
  • AND python2-rpm-4.14.3-37.2 is installed
  • BACK