VDB
MAGEIA-2021-167
MAGEIA-2021-167
PUBLISHED
This update from 4.16.1.2 to 4.16.1.3 fixes bugs several bugs the RPM package manager, including several security issues: * Fix arbitrary data copied from signature header past signature checking (CVE-2021-3421) * Fix signature check bypass with corrupted package (CVE-2021-20271) * Fix missing bounds checks in headerImport() and headerCheck() (CVE-2021-20266) * Fix missing sanity checks on header entry count and region data overlap * Fix access past end of header if the last entry is string type * Fix unsafe headerCopyLoad() still used in codebase
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mageia | rpm | 0, 4.16.1.3-1.mga8, 0 |
| Mageia | rawtherapee | 0, 5.8-3.1.mga8 |
Timeline
- Apr 2, 2021 CVE Updated
- Apr 2, 2021 CVE Published
References
- Updated rpm packages fix security vulnerabilities advisory
- Updated rpm packages fix security vulnerabilities issue
- Updated rpm packages fix security vulnerabilities issue
- Updated rawtherapee package fixes a crash bug on 32bit arch advisory
- Updated rawtherapee package fixes a crash bug on 32bit arch issue
- Updated rawtherapee package fixes a crash bug on 32bit arch issue