ALSA-2024:0463
Dashboard / Vulnerabilities / ALSA-2024:0463
ALSA-2024:0463
Summary: Moderate: rpm security update
Details: The RPM Package Manager (RPM) is a command-line driven package management system capable of installing, uninstalling, verifying, querying, and updating software packages. Security Fix(es): * rpm: TOCTOU race in checks for unsafe symlinks (CVE-2021-35937) * rpm: races with chown/chmod/capabilities calls during installation (CVE-2021-35938) * rpm: checks for unsafe symlinks are not performed for intermediary directories (CVE-2021-35939) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
References: https://access.redhat.com/errata/RHSA-2024:0463, https://access.redhat.com/security/cve/CVE-2021-35937, https://access.redhat.com/security/cve/CVE-2021-35938, https://access.redhat.com/security/cve/CVE-2021-35939, https://bugzilla.redhat.com/1964114, https://bugzilla.redhat.com/1964125, https://bugzilla.redhat.com/1964129, https://errata.almalinux.org/9/ALSA-2024-0463.html
Affected packages
Package
Name: python3-rpm
Purl: pkg:rpm/almalinux/python3-rpm
Affected ranges
Type: ECOSYSTEM
Events:
