RPM does not require subkeys to have a valid binding signature (CVE-2021-3521) References: - https://bugs.mageia.org/show_bug.cgi?id=29987 . MGASA-2022-0321 - Updated rpm packages fix security vulnerability Publication date: 10 Sep 2022 URL: https://advisories.mageia.org/MGASA-2022-0321.html Type: security Affected Mageia releases: 8 CVE: CVE-2021-3521 RPM does not require subkeys to have a valid binding signature (CVE-2021-3521) References: - https://bugs.mageia.org/show_bug.cgi?id=29987 - https://access.redhat.com/errata/RHSA-2022:0368 - https://www.cve.org/CVERecord?id=CVE-2021-3521 SRPMS: - 8/core/rpm-4.16.1.3-1.2.mga8 . Revised rpm archives address the vulnerability linked to signature bindings. Enhance defenses against possible risks.. RPM Packages, Mageia Security, Binding Signature. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.