NA

CVE-2021-35938

Published: 25/08/2022 Updated: 29/11/2022
CVSS v3 Base Score: 6.7 | Impact Score: 5.9 | Exploitability Score: 0.8
VMScore: 0

Vulnerability Summary

A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

rpm rpm

fedoraproject fedora 34

redhat enterprise linux 7.0

redhat enterprise linux 8.0

redhat enterprise linux 9.0

Vendor Advisories

Debian Bug report logs - #990543 rpm: CVE-2021-35937 CVE-2021-35938 CVE-2021-35939 Package: src:rpm; Maintainer for src:rpm is RPM packaging team <team+pkg-rpm@trackerdebianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Thu, 1 Jul 2021 15:45:01 UTC Severity: important Tags: security, upstream R ...
Synopsis Moderate: rpm security update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for rpm is now available for Red Hat Enterprise Linux 88 Extended Update SupportRed Hat Product Security has rated this upd ...
Synopsis Moderate: rpm security update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for rpm is now available for Red Hat Enterprise Linux 90 Extended Update SupportRed Hat Product Security has rated this upd ...
Synopsis Moderate: rpm security update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for rpm is now available for Red Hat Enterprise Linux 86 Extended Update SupportRed Hat Product Security has rated this upd ...
Synopsis Moderate: rpm security update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for rpm is now available for Red Hat Enterprise Linux 9Red Hat Product Security has rated this update as having a security i ...
Synopsis Moderate: rpm security update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for rpm is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security i ...