A flaw was found in RPM's signature check functionality when reading a package file. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package, whose signature header was modified, to cause RPM database corruption and execute code. The highest threat from this vulnerability is to data integrity, confidentiality, and system availability.
https://github.com/rpm-software-management/rpm/commit/d6a86b5e69e46cc283b1e06c92343319beb42e21
https://bugzilla.redhat.com/show_bug.cgi?id=1934125
https://security.gentoo.org/glsa/202107-43
https://www.starwindsoftware.com/security/sw-20220805-0002/
https://access.redhat.com/security/cve/CVE-2021-20271
https://access.redhat.com/errata/RHSA-2021:4975
https://access.redhat.com/errata/RHBA-2021:2854
https://access.redhat.com/errata/RHSA-2021:2791
https://access.redhat.com/errata/RHSA-2021:4771
Source: MITRE
Published: 2021-03-26
Updated: 2023-02-02
Type: CWE-345
Base Score: 5.1
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P
Impact Score: 6.4
Exploitability Score: 4.9
Severity: MEDIUM
Base Score: 7
Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Impact Score: 5.9
Exploitability Score: 1
Severity: HIGH