rpm package
opensuse/rpm&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/rpm&distro=openSUSE%20Tumbleweed
Vulnerabilities (7)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-44605 | Med | 5.5 | < 4.20.1-8.1 | 4.20.1-8.1 | Aug 5, 2026 | A flaw was found in the RPM Package Manager (RPM). A local user could be affected by a heap buffer overflow vulnerability when processing a specially crafted NDB database file. This issue arises from an error in how RPM handles certain calculations during file parsing, leading to | |
| CVE-2026-44604 | Hig | 7.0 | < 4.20.1-8.1 | 4.20.1-8.1 | May 28, 2026 | A command injection vulnerability was discovered in the `rpmuncompress` utility of RPM. When extracting certain archive formats (ZIP, 7z, GEM) to a specified destination directory, the tool inserts the archive's top-level folder name into a shell command without properly sanitizi | |
| CVE-2021-35939 | Med | 6.7 | < 4.18.0-1.1 | 4.18.0-1.1 | Aug 26, 2022 | It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to be created. A local unprivileged user who owns another ancestor directory could potentially use this flaw to gain root privileges. | |
| CVE-2021-35938 | Med | 6.7 | < 4.18.0-1.1 | 4.18.0-1.1 | Aug 25, 2022 | A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their privile | |
| CVE-2021-3521 | Med | 4.7 | < 4.17.1-1.1 | 4.17.1-1.1 | Aug 22, 2022 | There is a flaw in RPM's signature functionality. OpenPGP subkeys are associated with a primary key via a "binding signature." RPM does not check the binding signature of subkeys prior to importing them. If an attacker is able to add or socially engineer another party to add a ma | |
| CVE-2021-3421 | Med | 5.5 | < 4.16.1.3-3.2 | 4.16.1.3-3.2 | May 19, 2021 | A flaw was found in the RPM package in the read functionality. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package or compromise an RPM repository, to cause RPM database corruption. The highest threat from this vulnerability is to data | |
| CVE-2017-7500 | Hig | 7.3 | < 4.16.1.3-3.2 | 4.16.1.3-3.2 | Aug 13, 2018 | It was found that rpm did not properly handle RPM installations when a destination path was a symbolic link to a directory, possibly changing ownership and permissions of an arbitrary directory, and RPM files being placed in an arbitrary destination. An attacker, with write acces |
- affected < 4.20.1-8.1fixed 4.20.1-8.1
A flaw was found in the RPM Package Manager (RPM). A local user could be affected by a heap buffer overflow vulnerability when processing a specially crafted NDB database file. This issue arises from an error in how RPM handles certain calculations during file parsing, leading to
- affected < 4.20.1-8.1fixed 4.20.1-8.1
A command injection vulnerability was discovered in the `rpmuncompress` utility of RPM. When extracting certain archive formats (ZIP, 7z, GEM) to a specified destination directory, the tool inserts the archive's top-level folder name into a shell command without properly sanitizi
- affected < 4.18.0-1.1fixed 4.18.0-1.1
It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to be created. A local unprivileged user who owns another ancestor directory could potentially use this flaw to gain root privileges.
- affected < 4.18.0-1.1fixed 4.18.0-1.1
A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their privile
- affected < 4.17.1-1.1fixed 4.17.1-1.1
There is a flaw in RPM's signature functionality. OpenPGP subkeys are associated with a primary key via a "binding signature." RPM does not check the binding signature of subkeys prior to importing them. If an attacker is able to add or socially engineer another party to add a ma
- affected < 4.16.1.3-3.2fixed 4.16.1.3-3.2
A flaw was found in the RPM package in the read functionality. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package or compromise an RPM repository, to cause RPM database corruption. The highest threat from this vulnerability is to data
- affected < 4.16.1.3-3.2fixed 4.16.1.3-3.2
It was found that rpm did not properly handle RPM installations when a destination path was a symbolic link to a directory, possibly changing ownership and permissions of an arbitrary directory, and RPM files being placed in an arbitrary destination. An attacker, with write acces