6.7
CVSSv3

CVE-2021-35938

Published: 25/08/2022 Updated: 29/11/2022
CVSS v3 Base Score: 6.7 | Impact Score: 5.9 | Exploitability Score: 0.8

Vulnerability Summary

A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Most Upvoted Vulmon Research Post

There is no Researcher post for this vulnerability
Would you like to share something about it? Sign up now to share your knowledge with the community.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

rpm rpm

fedoraproject fedora 34

redhat enterprise linux 7.0

redhat enterprise linux 8.0

redhat enterprise linux 9.0

Vendor Advisories

Debian Bug report logs - #990543 rpm: CVE-2021-35937 CVE-2021-35938 CVE-2021-35939 Package: src:rpm; Maintainer for src:rpm is RPM packaging team <team+pkg-rpm@trackerdebianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Thu, 1 Jul 2021 15:45:01 UTC Severity: important Tags: security, upstream R ...

Github Repositories

CVE-2021-35938 A symbolic link issue was found in rpm It occurs when rpm sets the desired permissions and credentials after installing a file A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their privileges on the system The highest threat from this vulnerability is to data confidential

veracode-container-security-finding-parser Map Vulnerabilities into Different Layers of the Container Image Usage usage: mainpy [-h] [-i INSPECT_FILE] [-s SCAN_FILE] [-d] Example python mainpy Output: Scanned Image: juliantotzek/verademo1-tomcat:latest, Base Image OS Family: centos , Base Image OS Name: 761810 Base Image (based on the first Layer in veracode inspect comman