First published: Tue Mar 02 2021(Updated: )
A flaw was found in rpm. Given an RPM package signed by a trusted key, it is possible to modify it such that it still passes signature checks, but installing it corrupts the rpmdb.
Affected Software | Affected Version | How to fix |
---|---|---|
RPM Package Manager |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-1934125 is considered high due to the potential for RPM package corruption.
To fix REDHAT-BUG-1934125, update RPM Package Manager to the latest version provided by your distribution.
REDHAT-BUG-1934125 addresses vulnerabilities related to signature verification in RPM packages.
Users and systems running affected versions of RPM Package Manager are at risk due to REDHAT-BUG-1934125.
There are no official workarounds for REDHAT-BUG-1934125; updating the software is the recommended action.