Lucene search

K
osvGoogleOSV:CVE-2021-20271
HistoryMar 26, 2021 - 5:15 p.m.

CVE-2021-20271

2021-03-2617:15:13
Google
osv.dev
14
rpm
signature
functionality
package
attacker
database
corruption
code execution
vulnerability
data integrity
confidentiality
system availability

AI Score

6.7

Confidence

Low

EPSS

0.002

Percentile

61.2%

A flaw was found in RPM’s signature check functionality when reading a package file. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package, whose signature header was modified, to cause RPM database corruption and execute code. The highest threat from this vulnerability is to data integrity, confidentiality, and system availability.