Back to bug 1964129

Who When What Removed Added
Mauro Matteo Cascella 2021-06-09 09:27:23 UTC CC security-response-team
CC pmatilai
Depends On 1969334, 1969333, 1969335
Depends On 1969806, 1969804, 1969805
Mauro Matteo Cascella 2021-06-09 09:41:32 UTC Summary EMBARGOED: rpm: checks for unsafe symlinks are not performed for intermediary directories EMBARGOED rpm: checks for unsafe symlinks are not performed for intermediary directories
Mauro Matteo Cascella 2021-06-28 19:39:44 UTC Doc Text It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to be created. A local unprivileged user who owns another ancestor directory could potentially use this flaw to gain root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Mauro Matteo Cascella 2021-06-30 15:06:06 UTC Summary EMBARGOED rpm: checks for unsafe symlinks are not performed for intermediary directories EMBARGOED CVE-2021-35939 rpm: checks for unsafe symlinks are not performed for intermediary directories
Alias CVE-2021-35939
Blocks 1977374
Group security, qe_staff
CC caswilli, ffesti, igor.raits, mjw, packaging-team-maint, pmoravco, vmukhame
Summary EMBARGOED CVE-2021-35939 rpm: checks for unsafe symlinks are not performed for intermediary directories CVE-2021-35939 rpm: checks for unsafe symlinks are not performed for intermediary directories
Mauro Matteo Cascella 2021-06-30 15:21:57 UTC Depends On 1977848
Mauro Matteo Cascella 2021-07-08 10:22:01 UTC Depends On 1978167
Depends On 1978169
Depends On 1978170, 1978171
Comment 9 updated
Tomas Hoger 2021-09-16 08:36:48 UTC Depends On 2003067
Tomas Hoger 2022-04-06 11:57:58 UTC Depends On 2070455
Samantha N. Bueno 2022-05-12 03:56:47 UTC CC sbueno
Igor Raits 2022-08-30 12:14:15 UTC CC igor.raits
Mauro Matteo Cascella 2022-11-28 11:42:50 UTC Fixed In Version rpm 4.18.0
Mauro Matteo Cascella 2022-11-28 11:43:21 UTC Comment 14 updated
Mark Wielaard 2023-01-25 12:31:35 UTC CC mjw
Derrick 2023-05-09 19:47:06 UTC CC derrick.roach.ctr
Red Hat Bugzilla 2023-07-07 08:33:06 UTC Assignee security-response-team nobody
CC security-response-team

Back to bug 1964129