← Back

CVE-2021-3445

nvd nist
Published: May 19, 2021Modified: Nov 21, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 1.6 / Impact: 5.9
Source: NVD

Description

A flaw was found in libdnf's signature verification functionality in versions before 0.60.1. This flaw allows an attacker to achieve code execution if they can alter the header information of an RPM package and then trick a user or system into installing it. The highest risk of this vulnerability is to confidentiality, integrity, as well as system availability.

Affected (4)

1 product
Libdnf
1 product
Fedora
1 product
Enterprise Linux
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 0.60.1
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 33
Version 34
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 8.0

Timeline

No history available yet.