Signatures are written to disk before and read during verification, which might be subject to a race condition when a malicious local process or user is replacing the file. External Reference: https://www.mozilla.org/en-US/security/advisories/mfsa2021-14/#CVE-2021-29948
Acknowledgments: Name: the Mozilla project Upstream: Cure53
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2021:1353 https://access.redhat.com/errata/RHSA-2021:1353
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.1 Extended Update Support Via RHSA-2021:1351 https://access.redhat.com/errata/RHSA-2021:1351
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.2 Extended Update Support Via RHSA-2021:1352 https://access.redhat.com/errata/RHSA-2021:1352
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2021:1350 https://access.redhat.com/errata/RHSA-2021:1350
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2021-29948