OESA-2021-1224

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2021-1224
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2021-1224.json
JSON Data
https://api.test.osv.dev/v1/vulns/OESA-2021-1224
Upstream
Published
2021-06-22T11:02:58Z
Modified
2025-08-12T05:08:47.968643Z
Summary
libdnf security update
Details

A Library providing simplified C and Python API to libsolv.

Security Fix(es):

A flaw was found in libdnf's signature verification functionality in versions before 0.60.1. This flaw allows an attacker to achieve code execution if they can alter the header information of an RPM package and then trick a user or system into installing it. The highest risk of this vulnerability is to confidentiality, integrity, as well as system availability.(CVE-2021-3445)

Database specific
{
    "severity": "High"
}
References

Affected packages

openEuler:20.03-LTS-SP1 / libdnf

Package

Name
libdnf
Purl
pkg:rpm/openEuler/libdnf&distro=openEuler-20.03-LTS-SP1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.48.0-2.oe1

Ecosystem specific

{
    "x86_64": [
        "libdnf-devel-0.48.0-2.oe1.x86_64.rpm",
        "python2-hawkey-0.48.0-2.oe1.x86_64.rpm",
        "python3-hawkey-0.48.0-2.oe1.x86_64.rpm",
        "libdnf-debuginfo-0.48.0-2.oe1.x86_64.rpm",
        "python3-libdnf-0.48.0-2.oe1.x86_64.rpm",
        "libdnf-debugsource-0.48.0-2.oe1.x86_64.rpm",
        "libdnf-0.48.0-2.oe1.x86_64.rpm",
        "python2-libdnf-0.48.0-2.oe1.x86_64.rpm"
    ],
    "aarch64": [
        "python3-hawkey-0.48.0-2.oe1.aarch64.rpm",
        "libdnf-devel-0.48.0-2.oe1.aarch64.rpm",
        "python2-libdnf-0.48.0-2.oe1.aarch64.rpm",
        "libdnf-debuginfo-0.48.0-2.oe1.aarch64.rpm",
        "python3-libdnf-0.48.0-2.oe1.aarch64.rpm",
        "libdnf-debugsource-0.48.0-2.oe1.aarch64.rpm",
        "libdnf-0.48.0-2.oe1.aarch64.rpm",
        "python2-hawkey-0.48.0-2.oe1.aarch64.rpm"
    ],
    "src": [
        "libdnf-0.48.0-2.oe1.src.rpm"
    ]
}