Vulnerability Name:

CVE-2021-20271 (CCN-198961)

Assigned:2020-12-17
Published:2021-03-11
Updated:2023-02-12
Summary:A flaw was found in RPM's signature check functionality when reading a package file. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package, whose signature header was modified, to cause RPM database corruption and execute code. The highest threat from this vulnerability is to data integrity, confidentiality, and system availability.
CVSS v3 Severity:7.0 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H)
6.1 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
6.7 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H)
5.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): High
Privileges Required (PR): Low
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
6.7 Medium (REDHAT CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H)
5.8 Medium (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): High
Privileges Required (PR): Low
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:5.1 Medium (CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
6.0 Medium (CCN CVSS v2 Vector: AV:L/AC:H/Au:S/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): High
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-345
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2021-20271

Source: CCN
Type: Red Hat Bugzilla - Bug 1934125
(CVE-2021-20271) - CVE-2021-20271 rpm: Signature checks bypass via corrupted rpm package

Source: secalert@redhat.com
Type: Issue Tracking, Patch, Third Party Advisory
secalert@redhat.com

Source: XF
Type: UNKNOWN
rpm-cve202120271-code-exec(198961)

Source: CCN
Type: rpm GIT Repository
Be much more careful about copying data from the signature header

Source: secalert@redhat.com
Type: Patch, Third Party Advisory
secalert@redhat.com

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: secalert@redhat.com
Type: Third Party Advisory
secalert@redhat.com

Source: CCN
Type: IBM Security Bulletin 6493729 (Cloud Pak for Security)
Cloud Pak for Security is vulnerable to several CVEs

Source: CCN
Type: IBM Security Bulletin 6520474 (QRadar SIEM)
IBM QRadar SIEM Application Framework Base Image is vulnerable to using components with Known Vulnerabilities

Source: CCN
Type: IBM Security Bulletin 6568365 (QRadar Network Packet Capture)
IBM QRadar Network Packet Capture is using components with known vulnerabilities

Source: CCN
Type: IBM Security Bulletin 6601939 (QRadar Network Security)
IBM QRadar Network Security is affected by vulnerability in rpm. (CVE-2021-20271)

Source: CCN
Type: IBM Security Bulletin 6823145 (AIX)
Due to RPM, AIX is vulnerable to arbitrary code execution (CVE-2021-20271), RPM database corruption (CVE-2021-3421), and denial of service (CVE-2021-20266)

Source: secalert@redhat.com
Type: Third Party Advisory
secalert@redhat.com

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2021-20271

Vulnerable Configuration:Configuration RedHat 1:
  • cpe:/a:redhat:enterprise_linux:8:*:*:*:*:*:*:*
  • Configuration RedHat 2:
  • cpe:/a:redhat:enterprise_linux:8::appstream:*:*:*:*:*
  • Configuration RedHat 3:
  • cpe:/o:redhat:enterprise_linux:8:*:*:*:*:*:*:*
  • Configuration RedHat 4:
  • cpe:/o:redhat:enterprise_linux:8::baseos:*:*:*:*:*
  • Configuration RedHat 5:
  • cpe:/o:redhat:enterprise_linux:7:*:*:*:*:*:*:*
  • Configuration RedHat 6:
  • cpe:/o:redhat:enterprise_linux:7::client:*:*:*:*:*
  • Configuration RedHat 7:
  • cpe:/o:redhat:enterprise_linux:7::computenode:*:*:*:*:*
  • Configuration RedHat 8:
  • cpe:/o:redhat:enterprise_linux:7::server:*:*:*:*:*
  • Configuration RedHat 9:
  • cpe:/o:redhat:enterprise_linux:7::workstation:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/o:ibm:aix:7.1:*:*:*:*:*:*:*
  • OR cpe:/o:ibm:aix:7.2:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:qradar_security_information_and_event_manager:7.3:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:qradar_network_security:5.4.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:qradar_network_security:5.5.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:qradar_network_packet_capture:7.3:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:qradar_security_information_and_event_manager:7.4:-:*:*:*:*:*:*
  • OR cpe:/a:ibm:cloud_pak_for_security:1.7.0.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:cloud_pak_for_security:1.7.1.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:cloud_pak_for_security:1.7.2.0:*:*:*:*:*:*:*
  • OR cpe:/o:ibm:aix:7.3:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:8063
    P
    rpm-build-4.14.3-150300.55.1 on GA media (Moderate)
    2023-06-20
    oval:org.opensuse.security:def:7586
    P
    libcryptopp-devel-8.6.0-150400.1.6 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:7795
    P
    rpm-32bit-4.14.3-150300.55.1 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:7660
    P
    libruby2_5-2_5-2.5.9-150000.4.26.1 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:7677
    P
    libssh2-1-1.9.0-4.13.1 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:7575
    P
    libarchive-devel-3.5.1-150400.3.12.1 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:750
    P
    Security update for frr (Important)
    2022-09-12
    oval:org.opensuse.security:def:6130
    P
    Security update for u-boot (Important)
    2022-08-04
    oval:org.opensuse.security:def:6131
    P
    Security update for qpdf (Important)
    2022-08-04
    oval:org.opensuse.security:def:3651
    P
    Security update for gpg2 (Important)
    2022-07-25
    oval:org.opensuse.security:def:3189
    P
    libipa_hbac0-1.16.1-4.17.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3427
    P
    apache-commons-beanutils-1.9.2-3.3.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3501
    P
    glib2-lang-2.48.2-12.15.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:94819
    P
    rpm-32bit-4.14.3-150300.46.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:95057
    P
    rpm-build-4.14.3-150300.46.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:94613
    P
    libXp-devel-1.0.3-1.24 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:94919
    P
    libICE6-32bit-1.0.9-1.25 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:353
    P
    rpm-32bit-4.14.3-150300.46.1 on GA media (Moderate)
    2022-06-10
    oval:org.opensuse.security:def:95408
    P
    Security update for php8 (Low)
    2022-06-02
    oval:org.opensuse.security:def:4569
    P
    Security update for the Linux Kernel (Live Patch 24 for SLE 12 SP5) (Important)
    2022-04-13
    oval:org.opensuse.security:def:102121
    P
    Security update for the Linux Kernel (Important)
    2022-04-12
    oval:org.opensuse.security:def:101632
    P
    Security update for systemd (Moderate)
    2022-01-11
    oval:com.redhat.rhsa:def:20214785
    P
    RHSA-2021:4785: rpm security update (Moderate)
    2021-11-23
    oval:org.opensuse.security:def:4510
    P
    Security update for the Linux Kernel (Live Patch 13 for SLE 12 SP5) (Important)
    2021-11-17
    oval:org.opensuse.security:def:111088
    P
    Security update for rpm (Important)
    2021-10-18
    oval:org.opensuse.security:def:73712
    P
    Security update for rpm (Important)
    2021-10-15
    oval:org.opensuse.security:def:5860
    P
    Security update for rpm (Important)
    2021-10-15
    oval:org.opensuse.security:def:95969
    P
    Security update for rpm (Important)
    2021-10-15
    oval:org.opensuse.security:def:117812
    P
    Security update for rpm (Important)
    2021-10-15
    oval:org.opensuse.security:def:108787
    P
    Security update for rpm (Important)
    2021-10-15
    oval:org.opensuse.security:def:68749
    P
    Security update for rpm (Important)
    2021-10-15
    oval:org.opensuse.security:def:65599
    P
    Security update for rpm (Important)
    2021-10-15
    oval:org.opensuse.security:def:76017
    P
    Security update for rpm (Important)
    2021-10-15
    oval:org.opensuse.security:def:95983
    P
    Security update for rpm (Important)
    2021-10-15
    oval:org.opensuse.security:def:118372
    P
    Security update for rpm (Important)
    2021-10-15
    oval:org.opensuse.security:def:109286
    P
    Security update for rpm (Important)
    2021-10-15
    oval:org.opensuse.security:def:102620
    P
    Security update for rpm (Important)
    2021-10-15
    oval:org.opensuse.security:def:95907
    P
    Security update for rpm (Important)
    2021-10-15
    oval:org.opensuse.security:def:107992
    P
    Security update for rpm (Important)
    2021-10-15
    oval:org.opensuse.security:def:68664
    P
    Security update for rpm (Important)
    2021-10-15
    oval:org.opensuse.security:def:64590
    P
    Security update for rpm (Important)
    2021-10-15
    oval:org.opensuse.security:def:74667
    P
    Security update for rpm (Important)
    2021-10-15
    oval:org.opensuse.security:def:101326
    P
    Security update for rpm (Important)
    2021-10-15
    oval:org.opensuse.security:def:118409
    P
    Security update for rpm (Important)
    2021-10-15
    oval:org.opensuse.security:def:109318
    P
    Security update for rpm (Important)
    2021-10-15
    oval:org.opensuse.security:def:66949
    P
    Security update for rpm (Important)
    2021-10-15
    oval:org.opensuse.security:def:42128
    P
    Security update for rpm (Important)
    2021-10-15
    oval:org.opensuse.security:def:102652
    P
    Security update for rpm (Important)
    2021-10-15
    oval:org.opensuse.security:def:95939
    P
    Security update for rpm (Important)
    2021-10-15
    oval:org.opensuse.security:def:117506
    P
    Security update for rpm (Important)
    2021-10-15
    oval:org.opensuse.security:def:108298
    P
    Security update for rpm (Important)
    2021-10-15
    oval:org.opensuse.security:def:76529
    P
    Security update for rpm (Important)
    2021-10-15
    oval:org.opensuse.security:def:111662
    P
    Security update for rpm (Important)
    2021-08-17
    oval:org.opensuse.security:def:111663
    P
    Security update for libdnf (Moderate)
    2021-08-13
    oval:org.opensuse.security:def:67220
    P
    Security update for libdnf (Moderate)
    2021-08-13
    oval:org.opensuse.security:def:76288
    P
    Security update for libdnf (Moderate)
    2021-08-13
    oval:org.opensuse.security:def:99402
    P
    (Important)
    2021-08-12
    oval:org.opensuse.security:def:93755
    P
    (Important)
    2021-08-12
    oval:org.opensuse.security:def:100644
    P
    (Important)
    2021-08-12
    oval:org.opensuse.security:def:93260
    P
    (Important)
    2021-08-12
    oval:org.opensuse.security:def:76546
    P
    Security update for rpm (Important)
    2021-08-12
    oval:org.opensuse.security:def:1118
    P
    Security update for rpm (Important)
    2021-08-12
    oval:org.opensuse.security:def:73862
    P
    Security update for rpm (Important)
    2021-08-12
    oval:org.opensuse.security:def:99665
    P
    (Important)
    2021-08-12
    oval:org.opensuse.security:def:68766
    P
    Security update for rpm (Important)
    2021-08-12
    oval:org.opensuse.security:def:93969
    P
    (Important)
    2021-08-12
    oval:org.opensuse.security:def:65658
    P
    Security update for rpm (Important)
    2021-08-12
    oval:org.opensuse.security:def:76287
    P
    Security update for rpm (Important)
    2021-08-12
    oval:org.opensuse.security:def:101481
    P
    Security update for rpm (Important)
    2021-08-12
    oval:org.opensuse.security:def:93418
    P
    (Important)
    2021-08-12
    oval:org.opensuse.security:def:1548
    P
    Security update for rpm (Important)
    2021-08-12
    oval:org.opensuse.security:def:99979
    P
    (Important)
    2021-08-12
    oval:org.opensuse.security:def:94181
    P
    (Important)
    2021-08-12
    oval:org.opensuse.security:def:101796
    P
    Security update for rpm (Important)
    2021-08-12
    oval:org.opensuse.security:def:68675
    P
    Security update for rpm (Important)
    2021-08-12
    oval:org.opensuse.security:def:93574
    P
    (Important)
    2021-08-12
    oval:org.opensuse.security:def:64740
    P
    Security update for rpm (Important)
    2021-08-12
    oval:org.opensuse.security:def:1571
    P
    Security update for rpm (Important)
    2021-08-12
    oval:org.opensuse.security:def:74726
    P
    Security update for rpm (Important)
    2021-08-12
    oval:org.opensuse.security:def:100315
    P
    (Important)
    2021-08-12
    oval:org.opensuse.security:def:94392
    P
    (Important)
    2021-08-12
    oval:org.opensuse.security:def:67219
    P
    Security update for rpm (Important)
    2021-08-12
    oval:org.opensuse.security:def:93100
    P
    (Important)
    2021-08-12
    oval:com.redhat.rhsa:def:20212574
    P
    RHSA-2021:2574: rpm security update (Moderate)
    2021-06-29
    BACK
    ibm aix 7.1
    ibm aix 7.2
    ibm qradar security information and event manager 7.3
    ibm qradar network security 5.4.0
    ibm qradar network security 5.5.0
    ibm qradar network packet capture 7.3
    ibm qradar security information and event manager 7.4 -
    ibm cloud pak for security 1.7.0.0
    ibm cloud pak for security 1.7.1.0
    ibm cloud pak for security 1.7.2.0
    ibm aix 7.3