CVE-2021-3445

HIGH

libdnf < 0.60.1 - Remote Code Execution via Altered RPM Package Header

Title source: llm
STIX 2.1

Description

A flaw was found in libdnf's signature verification functionality in versions before 0.60.1. This flaw allows an attacker to achieve code execution if they can alter the header information of an RPM package and then trick a user or system into installing it. The highest risk of this vulnerability is to confidentiality, integrity, as well as system availability.

References (3)

Core 3
Core References
Issue Tracking, Mitigation, Third Party Advisory x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=1932079

Scores

CVSS v3 7.5
EPSS 0.0004
EPSS Percentile 11.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-347
Status published
Products (4)
fedoraproject/fedora 33
fedoraproject/fedora 34
redhat/enterprise_linux 8.0
rpm/libdnf < 0.60.1
Published May 19, 2021
Tracked Since Feb 18, 2026