Vulnerability Description
It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to be created. A local unprivileged user who owns another ancestor directory could potentially use this flaw to gain root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Rpm | Rpm | < 4.18 |
| Redhat | Enterprise Linux | 8.0 |
Related Weaknesses (CWE)
References
- https://access.redhat.com/security/cve/CVE-2021-35939Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1964129ExploitIssue TrackingThird Party Advisory
- https://github.com/rpm-software-management/rpm/commit/96ec957e281220f8e137a2d5ebPatchThird Party Advisory
- https://github.com/rpm-software-management/rpm/pull/1919PatchThird Party Advisory
- https://rpm.org/wiki/Releases/4.18.0Release NotesVendor Advisory
- https://security.gentoo.org/glsa/202210-22Third Party Advisory
- https://access.redhat.com/security/cve/CVE-2021-35939Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1964129ExploitIssue TrackingThird Party Advisory
- https://github.com/rpm-software-management/rpm/commit/96ec957e281220f8e137a2d5ebPatchThird Party Advisory
- https://github.com/rpm-software-management/rpm/pull/1919PatchThird Party Advisory
- https://rpm.org/wiki/Releases/4.18.0Release NotesVendor Advisory
- https://security.gentoo.org/glsa/202210-22Third Party Advisory
FAQ
What is CVE-2021-35939?
CVE-2021-35939 is a vulnerability with a CVSS score of 6.7 (MEDIUM). It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to be created. A local unprivileged user who owns anot...
How severe is CVE-2021-35939?
CVE-2021-35939 has been rated MEDIUM with a CVSS base score of 6.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-35939?
Check the references section above for vendor advisories and patch information. Affected products include: Rpm Rpm, Redhat Enterprise Linux.