UBUNTU-CVE-2021-3521

Source
https://ubuntu.com/security/CVE-2021-3521
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-3521.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2021-3521
Related
Published
2022-08-22T15:15:00Z
Modified
2024-10-15T14:08:14Z
Severity
  • 4.7 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N CVSS Calculator
Summary
[none]
Details

There is a flaw in RPM's signature functionality. OpenPGP subkeys are associated with a primary key via a "binding signature." RPM does not check the binding signature of subkeys prior to importing them. If an attacker is able to add or socially engineer another party to add a malicious subkey to a legitimate public key, RPM could wrongly trust a malicious signature. The greatest impact of this flaw is to data integrity. To exploit this flaw, an attacker must either compromise an RPM repository or convince an administrator to install an untrusted RPM or public key. It is strongly recommended to only use RPMs and public keys from trusted sources.

References

Affected packages

Ubuntu:Pro:14.04:LTS / rpm

Package

Name
rpm
Purl
pkg:deb/ubuntu/rpm?arch=src?distro=trusty/esm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

4.*

4.11.1-2
4.11.1-3
4.11.1-3ubuntu0.1
4.11.1-3ubuntu0.1+esm1

Ecosystem specific

{
    "ubuntu_priority": "negligible"
}

Ubuntu:Pro:16.04:LTS / rpm

Package

Name
rpm
Purl
pkg:deb/ubuntu/rpm?arch=src?distro=esm-apps/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

4.*

4.12.0.1+dfsg1-3build2
4.12.0.1+dfsg1-3build3
4.12.0.1+dfsg1-3ubuntu0.1~esm1

Ecosystem specific

{
    "ubuntu_priority": "negligible"
}

Ubuntu:Pro:18.04:LTS / rpm

Package

Name
rpm
Purl
pkg:deb/ubuntu/rpm?arch=src?distro=esm-apps/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

4.*

4.12.0.2+dfsg1-2build2
4.14.0+dfsg1-2
4.14.1+dfsg1-2
4.14.1+dfsg1-2ubuntu0.1~esm1

Ecosystem specific

{
    "ubuntu_priority": "negligible"
}

Ubuntu:20.04:LTS / rpm

Package

Name
rpm
Purl
pkg:deb/ubuntu/rpm?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

4.*

4.14.2.1+dfsg1-1
4.14.2.1+dfsg1-1build1
4.14.2.1+dfsg1-1build2

Ecosystem specific

{
    "ubuntu_priority": "negligible"
}

Ubuntu:22.04:LTS / rpm

Package

Name
rpm
Purl
pkg:deb/ubuntu/rpm?arch=src?distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

4.*

4.16.1.2+dfsg1-3ubuntu1
4.16.1.2+dfsg1-3ubuntu3
4.17.0+dfsg1-1
4.17.0+dfsg1-3
4.17.0+dfsg1-4
4.17.0+dfsg1-4build1

Ecosystem specific

{
    "ubuntu_priority": "negligible"
}

Ubuntu:24.10 / rpm

Package

Name
rpm
Purl
pkg:deb/ubuntu/rpm?arch=src?distro=oracular

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

4.*

4.18.2+dfsg-2.1build2
4.19.1.1+dfsg-1

Ecosystem specific

{
    "ubuntu_priority": "negligible"
}

Ubuntu:24.04:LTS / rpm

Package

Name
rpm
Purl
pkg:deb/ubuntu/rpm?arch=src?distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

4.*

4.18.0+dfsg-1build1
4.18.0+dfsg-1build2
4.18.2+dfsg-1
4.18.2+dfsg-2
4.18.2+dfsg-2.1build1
4.18.2+dfsg-2.1build2

Ecosystem specific

{
    "ubuntu_priority": "negligible"
}