rpm-4.8.0-59.0.2.AXS4

エラータID: AXSA:2021-2775:09

Release date: 
Wednesday, December 15, 2021 - 07:37
Subject: 
rpm-4.8.0-59.0.2.AXS4
Affected Channels: 
Asianux Server 4 for x86_64
Asianux Server 4 for x86
Severity: 
Moderate
Description: 

The RPM Package Manager (RPM) is a command-line driven package management system
capable of installing, uninstalling, verifying, querying, and updating software
packages.

Security Fix(es):

rpm: Signature checks bypass via corrupted rpm package (CVE-2021-20271)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE page(s)
listed in the References section.

CVE(s):
CVE-2021-20271
A flaw was found in RPM's signature check functionality when reading a package file. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package, whose signature header was modified, to cause RPM database corruption and execute code. The highest threat from this vulnerability is to data integrity, confidentiality, and system availability.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. rpm-4.8.0-59.0.2.AXS4.src.rpm
    MD5: 03c2c620aa92fc0495571de7d7a4c666
    SHA-256: 841ecc9b9bc7b70291498bc2297cf75529eeac3d83589e4e31c96c4382f3593d
    Size: 3.65 MB

Asianux Server 4 for x86
  1. rpm-4.8.0-59.0.2.AXS4.i686.rpm
    MD5: 1b295a6f181d7ded05307b761a4491e7
    SHA-256: a891209510e78e2397ed31a2b9cfc617799fad35dc63072c3af4ef38c9e39ec4
    Size: 904.92 kB
  2. rpm-build-4.8.0-59.0.2.AXS4.i686.rpm
    MD5: 3ec2e415354fb1c029315c9a404daae2
    SHA-256: 29635833c11c32e677c31617cb5902e652f94ed285341ec54b4ff7449ef44313
    Size: 132.03 kB
  3. rpm-devel-4.8.0-59.0.2.AXS4.i686.rpm
    MD5: 5081600e50f7a68525b4db349a649273
    SHA-256: 68a8e3aff03f944fffe156e841561da9edebef17332aff831a09bb7860fb8e3f
    Size: 96.76 kB
  4. rpm-libs-4.8.0-59.0.2.AXS4.i686.rpm
    MD5: 355fa1fa64f499e8d8d7876dbceb8af5
    SHA-256: 30eeca22261cab2f5f86dad102ee91fd8b3b9387dc544d0a2aec9c3c59fc390b
    Size: 320.96 kB
  5. rpm-python-4.8.0-59.0.2.AXS4.i686.rpm
    MD5: 0edb2d97febd22264d59610da53a7bec
    SHA-256: 41879edf2002cef071aef0e4f352c90a10fa608a2a3d349317d894fcd18f3ba8
    Size: 59.03 kB

Asianux Server 4 for x86_64
  1. rpm-4.8.0-59.0.2.AXS4.x86_64.rpm
    MD5: 0b1b80e3b1dda2f75178805de510e436
    SHA-256: 7fd64c4660c0d4b9e44952e57a7c7a9ab4c173fa57b401f82aa16bc91f404556
    Size: 905.58 kB
  2. rpm-build-4.8.0-59.0.2.AXS4.x86_64.rpm
    MD5: 7e211551cd028f24b275d90c9283b17f
    SHA-256: 10d14ce92a23ca0193f86ec6a0d2403ee41c05112dbac79802dc7c18236f49fa
    Size: 130.76 kB
  3. rpm-devel-4.8.0-59.0.2.AXS4.x86_64.rpm
    MD5: 7eabf86917887e85c913e6028a0c4ce7
    SHA-256: a76d774f78b1eed2e22de136277995224d2b83dbccceec83e569534a79ead78f
    Size: 96.66 kB
  4. rpm-libs-4.8.0-59.0.2.AXS4.x86_64.rpm
    MD5: 748176b0359a5bce71ed7afb231f0db4
    SHA-256: 8fcdaa96c79bd19fd3ea9eeaac5c2d1eb4e54d7ee73ca6349d755ddebcb4c366
    Size: 317.70 kB
  5. rpm-python-4.8.0-59.0.2.AXS4.x86_64.rpm
    MD5: 61cff26d93e9e202721038f2429f1c64
    SHA-256: 666b97b583e6ea28f40f9a0800a26688fcbe4a6ec7b07f5e4568ce270f91f7ca
    Size: 60.01 kB
  6. rpm-devel-4.8.0-59.0.2.AXS4.i686.rpm
    MD5: 5081600e50f7a68525b4db349a649273
    SHA-256: 68a8e3aff03f944fffe156e841561da9edebef17332aff831a09bb7860fb8e3f
    Size: 96.76 kB
  7. rpm-libs-4.8.0-59.0.2.AXS4.i686.rpm
    MD5: 355fa1fa64f499e8d8d7876dbceb8af5
    SHA-256: 30eeca22261cab2f5f86dad102ee91fd8b3b9387dc544d0a2aec9c3c59fc390b
    Size: 320.96 kB