Improper Verification of Cryptographic Signature in libdnf - CVE-2021-3445

 

Improper Verification of Cryptographic Signature in libdnf - CVE-2021-3445

Published: June 30, 2021


Vulnerability identifier: #VU54480
CSH Severity: Medium
CVSS v4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-3445
CWE-ID: CWE-347
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to insufficient verification of cryptographic signature in libdnf. A remote attacker can create a specially crafted RPM package with altered header information, trick the victim into installing it and compromise the affected system.


Affected software

libdnf
libdnf (Red Hat package)
dnf-plugins-core (Red Hat package)
dnf (Red Hat package)
libdnf
python3-hawkey
libdnf-devel
python2-libdnf
libdnf-debuginfo
python3-libdnf
libdnf-debugsource
python2-hawkey
rpm-ostree
Cloud Pak for Security (CP4S)
Red Hat Enterprise Linux for IBM z Systems
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
openEuler
Fedora
Migration Toolkit for Containers
Red Hat OpenShift Serverless
Red Hat Advanced Cluster Management for Kubernetes
Red Hat Advanced Cluster Security for Kubernetes
Red Hat OpenStack

How to mitigate CVE-2021-3445

Install updates from vendor's website.

libdnf - update to 0.60.1
libdnf (Red Hat package) - update to 0.63.0-3.el8
Cloud Pak for Security (CP4S) - update to 1.10.7.0
dnf-plugins-core (Red Hat package) - update to 4.0.21-3.el8
dnf (Red Hat package) - update to 4.7.0-4.el8
libdnf - update to 0.48.0-2
python3-hawkey - update to 0.48.0-2
libdnf-devel - update to 0.48.0-2
python2-libdnf - update to 0.48.0-2
libdnf-debuginfo - update to 0.48.0-2
python3-libdnf - update to 0.48.0-2
libdnf-debugsource - update to 0.48.0-2
python2-hawkey - update to 0.48.0-2
Migration Toolkit for Containers - update to 1.5.4
Red Hat OpenShift Serverless - update to 1.20.0
Red Hat Advanced Cluster Management for Kubernetes - update to 2.2.10
Red Hat Advanced Cluster Security for Kubernetes - update to 3.67
Red Hat OpenStack - update to 16.2
rpm-ostree - addressed in versions 2021.4-1.fc33, 2021.4-1.fc34

External References

Related Security Bulletins