CVE-2021-20266
30.04.2021, 12:15
A flaw was found in RPM's hdrblobInit() in lib/header.c. This flaw allows an attacker who can modify the rpmdb to cause an out-of-bounds read. The highest threat from this vulnerability is to system availability.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| rpm | rpm | 𝑥 < 4.16.1.3 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| python3-rpm |
| ||||||||||||||||||||||||||||||||||||||||||
| rpm |
| ||||||||||||||||||||||||||||||||||||||||||
| rpm-32bit |
| ||||||||||||||||||||||||||||||||||||||||||
| rpm-build |
| ||||||||||||||||||||||||||||||||||||||||||
| rpm-devel |
| ||||||||||||||||||||||||||||||||||||||||||
| rpm-imaevmsign |
| ||||||||||||||||||||||||||||||||||||||||||
| rpm-python |
|
Red Hat Enterprise Linux Releases
Red Hat Product | |||
|---|---|---|---|
| python3-rpm |
| ||
| rpm |
| ||
| rpm-apidocs |
| ||
| rpm-build |
| ||
| rpm-build-libs |
| ||
| rpm-cron |
| ||
| rpm-devel |
| ||
| rpm-libs |
| ||
| rpm-plugin-fapolicyd |
| ||
| rpm-plugin-ima |
| ||
| rpm-plugin-prioreset |
| ||
| rpm-plugin-selinux |
| ||
| rpm-plugin-syslog |
| ||
| rpm-plugin-systemd-inhibit |
| ||
| rpm-sign |
|
Common Weakness Enumeration
References