USN-5273-1

See a problem?
Source
https://ubuntu.com/security/notices/USN-5273-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-5273-1.json
JSON Data
https://api.osv.dev/v1/vulns/USN-5273-1
Related
Published
2022-07-21T06:56:30.920953Z
Modified
2022-07-21T06:56:30.920953Z
Summary
rpm vulnerabilities
Details

Demi M. Obenour discovered that RPM Package Manager incorrectly handled certain files. An attacker could possibly use this issue to corrupt the database and cause a denial of service. (CVE-2021-3421, CVE-2021-20271)

Demi M. Obenour discovered that RPM Package Manager incorrectly handled memory when processing certain data from the database. An attacker could possibly use this issue to cause a denial of service. This issue only affects Ubuntu 18.04 ESM and Ubuntu 20.04 ESM. (CVE-2021-20266)

References

Affected packages

Ubuntu:Pro:16.04:LTS / rpm

Package

Name
rpm
Purl
pkg:deb/ubuntu/rpm@4.12.0.1+dfsg1-3ubuntu0.1~esm1?arch=src?distro=esm-apps/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.12.0.1+dfsg1-3ubuntu0.1~esm1

Affected versions

4.*

4.12.0.1+dfsg1-3build2
4.12.0.1+dfsg1-3build3

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "binaries": [
        {
            "librpm-dev": "4.12.0.1+dfsg1-3ubuntu0.1~esm1",
            "librpmbuild3": "4.12.0.1+dfsg1-3ubuntu0.1~esm1",
            "debugedit-dbgsym": "4.12.0.1+dfsg1-3ubuntu0.1~esm1",
            "python-rpm": "4.12.0.1+dfsg1-3ubuntu0.1~esm1",
            "librpmio3-dbgsym": "4.12.0.1+dfsg1-3ubuntu0.1~esm1",
            "librpmsign3": "4.12.0.1+dfsg1-3ubuntu0.1~esm1",
            "python3-rpm": "4.12.0.1+dfsg1-3ubuntu0.1~esm1",
            "librpm-dev-dbgsym": "4.12.0.1+dfsg1-3ubuntu0.1~esm1",
            "rpm-i18n": "4.12.0.1+dfsg1-3ubuntu0.1~esm1",
            "librpmsign3-dbgsym": "4.12.0.1+dfsg1-3ubuntu0.1~esm1",
            "rpm-common-dbgsym": "4.12.0.1+dfsg1-3ubuntu0.1~esm1",
            "librpm3": "4.12.0.1+dfsg1-3ubuntu0.1~esm1",
            "librpmio3": "4.12.0.1+dfsg1-3ubuntu0.1~esm1",
            "librpmbuild3-dbgsym": "4.12.0.1+dfsg1-3ubuntu0.1~esm1",
            "rpm-dbgsym": "4.12.0.1+dfsg1-3ubuntu0.1~esm1",
            "debugedit": "4.12.0.1+dfsg1-3ubuntu0.1~esm1",
            "rpm": "4.12.0.1+dfsg1-3ubuntu0.1~esm1",
            "rpm2cpio-dbgsym": "4.12.0.1+dfsg1-3ubuntu0.1~esm1",
            "librpm-dbg": "4.12.0.1+dfsg1-3ubuntu0.1~esm1",
            "rpm2cpio": "4.12.0.1+dfsg1-3ubuntu0.1~esm1",
            "rpm-common": "4.12.0.1+dfsg1-3ubuntu0.1~esm1",
            "librpm3-dbgsym": "4.12.0.1+dfsg1-3ubuntu0.1~esm1"
        }
    ]
}

Ubuntu:Pro:18.04:LTS / rpm

Package

Name
rpm
Purl
pkg:deb/ubuntu/rpm@4.14.1+dfsg1-2ubuntu0.1~esm1?arch=src?distro=esm-apps/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.14.1+dfsg1-2ubuntu0.1~esm1

Affected versions

4.*

4.12.0.2+dfsg1-2build2
4.14.0+dfsg1-2
4.14.1+dfsg1-2

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "binaries": [
        {
            "librpmio8": "4.14.1+dfsg1-2ubuntu0.1~esm1",
            "librpm-dev": "4.14.1+dfsg1-2ubuntu0.1~esm1",
            "python-rpm": "4.14.1+dfsg1-2ubuntu0.1~esm1",
            "debugedit-dbgsym": "4.14.1+dfsg1-2ubuntu0.1~esm1",
            "librpmsign8": "4.14.1+dfsg1-2ubuntu0.1~esm1",
            "librpmbuild8-dbgsym": "4.14.1+dfsg1-2ubuntu0.1~esm1",
            "python3-rpm": "4.14.1+dfsg1-2ubuntu0.1~esm1",
            "rpm-i18n": "4.14.1+dfsg1-2ubuntu0.1~esm1",
            "librpmbuild8": "4.14.1+dfsg1-2ubuntu0.1~esm1",
            "python3-rpm-dbgsym": "4.14.1+dfsg1-2ubuntu0.1~esm1",
            "rpm-common-dbgsym": "4.14.1+dfsg1-2ubuntu0.1~esm1",
            "librpm8-dbgsym": "4.14.1+dfsg1-2ubuntu0.1~esm1",
            "rpm-dbgsym": "4.14.1+dfsg1-2ubuntu0.1~esm1",
            "python-rpm-dbgsym": "4.14.1+dfsg1-2ubuntu0.1~esm1",
            "debugedit": "4.14.1+dfsg1-2ubuntu0.1~esm1",
            "rpm": "4.14.1+dfsg1-2ubuntu0.1~esm1",
            "rpm-common": "4.14.1+dfsg1-2ubuntu0.1~esm1",
            "rpm2cpio": "4.14.1+dfsg1-2ubuntu0.1~esm1",
            "librpmsign8-dbgsym": "4.14.1+dfsg1-2ubuntu0.1~esm1",
            "rpm2cpio-dbgsym": "4.14.1+dfsg1-2ubuntu0.1~esm1",
            "librpmio8-dbgsym": "4.14.1+dfsg1-2ubuntu0.1~esm1",
            "librpm8": "4.14.1+dfsg1-2ubuntu0.1~esm1"
        }
    ]
}

Ubuntu:Pro:20.04:LTS / rpm

Package

Name
rpm
Purl
pkg:deb/ubuntu/rpm@4.14.2.1+dfsg1-1ubuntu0.1~esm1?arch=src?distro=esm-apps/focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.14.2.1+dfsg1-1ubuntu0.1~esm1

Affected versions

4.*

4.14.2.1+dfsg1-1
4.14.2.1+dfsg1-1build1
4.14.2.1+dfsg1-1build2

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "binaries": [
        {
            "librpmio8": "4.14.2.1+dfsg1-1ubuntu0.1~esm1",
            "librpm-dev": "4.14.2.1+dfsg1-1ubuntu0.1~esm1",
            "python-rpm": "4.14.2.1+dfsg1-1ubuntu0.1~esm1",
            "debugedit-dbgsym": "4.14.2.1+dfsg1-1ubuntu0.1~esm1",
            "librpmsign8": "4.14.2.1+dfsg1-1ubuntu0.1~esm1",
            "librpmbuild8-dbgsym": "4.14.2.1+dfsg1-1ubuntu0.1~esm1",
            "python3-rpm": "4.14.2.1+dfsg1-1ubuntu0.1~esm1",
            "rpm-i18n": "4.14.2.1+dfsg1-1ubuntu0.1~esm1",
            "librpmbuild8": "4.14.2.1+dfsg1-1ubuntu0.1~esm1",
            "python3-rpm-dbgsym": "4.14.2.1+dfsg1-1ubuntu0.1~esm1",
            "rpm-common-dbgsym": "4.14.2.1+dfsg1-1ubuntu0.1~esm1",
            "librpm8-dbgsym": "4.14.2.1+dfsg1-1ubuntu0.1~esm1",
            "rpm-dbgsym": "4.14.2.1+dfsg1-1ubuntu0.1~esm1",
            "python-rpm-dbgsym": "4.14.2.1+dfsg1-1ubuntu0.1~esm1",
            "debugedit": "4.14.2.1+dfsg1-1ubuntu0.1~esm1",
            "rpm": "4.14.2.1+dfsg1-1ubuntu0.1~esm1",
            "rpm-common": "4.14.2.1+dfsg1-1ubuntu0.1~esm1",
            "rpm2cpio": "4.14.2.1+dfsg1-1ubuntu0.1~esm1",
            "librpmsign8-dbgsym": "4.14.2.1+dfsg1-1ubuntu0.1~esm1",
            "rpm2cpio-dbgsym": "4.14.2.1+dfsg1-1ubuntu0.1~esm1",
            "librpmio8-dbgsym": "4.14.2.1+dfsg1-1ubuntu0.1~esm1",
            "librpm8": "4.14.2.1+dfsg1-1ubuntu0.1~esm1"
        }
    ]
}