rpm package
almalinux/aardvark-dns
pkg:rpm/almalinux/aardvark-dns
Vulnerabilities (105)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2022-27191 | Hig | 7.5 | < 2:1.0.1-35.module_el8.7.0+3344+5bcd850f | 2:1.0.1-35.module_el8.7.0+3344+5bcd850f | Mar 18, 2022 | The golang.org/x/crypto/ssh package before 0.0.0-20220314234659-1baeb1ce4c0b for Go allows an attacker to crash a server in certain circumstances involving AddHostKey. | |
| CVE-2022-21698 | Hig | 7.5 | < 2:1.0.1-27.module_el8.6.0+2878+e681bc44 | 2:1.0.1-27.module_el8.6.0+2878+e681bc44 | Feb 15, 2022 | client_golang is the instrumentation library for Go applications in Prometheus, and the promhttp package in client_golang provides tooling around HTTP servers and clients. In client_golang prior to version 1.11.1, HTTP server is susceptible to a Denial of Service through unbounde | |
| CVE-2021-4024 | Med | 6.5 | < 2:1.10.1-2.module_el8.10.0+3909+6e1c1eb7 | 2:1.10.1-2.module_el8.10.0+3909+6e1c1eb7 | Dec 23, 2021 | A flaw was found in podman. The `podman machine` function (used to create and manage Podman virtual machine containing a Podman process) spawns a `gvproxy` process on the host system. The `gvproxy` API is accessible on port 7777 on all IP addresses on the host. If that port is op | |
| CVE-2021-33198 | Hig | 7.5 | < 2:1.10.1-2.module_el8.10.0+3909+6e1c1eb7 | 2:1.10.1-2.module_el8.10.0+3909+6e1c1eb7 | Aug 2, 2021 | In Go before 1.15.13 and 1.16.x before 1.16.5, there can be a panic for a large exponent to the math/big.Rat SetString or UnmarshalText method. | |
| CVE-2019-19921 | Hig | 7.0 | < 2:1.0.1-38.module_el8.9.0+3627+db8ec155 | 2:1.0.1-38.module_el8.9.0+3627+db8ec155 | Feb 12, 2020 | runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. (This vul |
- affected < 2:1.0.1-35.module_el8.7.0+3344+5bcd850ffixed 2:1.0.1-35.module_el8.7.0+3344+5bcd850f
The golang.org/x/crypto/ssh package before 0.0.0-20220314234659-1baeb1ce4c0b for Go allows an attacker to crash a server in certain circumstances involving AddHostKey.
- affected < 2:1.0.1-27.module_el8.6.0+2878+e681bc44fixed 2:1.0.1-27.module_el8.6.0+2878+e681bc44
client_golang is the instrumentation library for Go applications in Prometheus, and the promhttp package in client_golang provides tooling around HTTP servers and clients. In client_golang prior to version 1.11.1, HTTP server is susceptible to a Denial of Service through unbounde
- affected < 2:1.10.1-2.module_el8.10.0+3909+6e1c1eb7fixed 2:1.10.1-2.module_el8.10.0+3909+6e1c1eb7
A flaw was found in podman. The `podman machine` function (used to create and manage Podman virtual machine containing a Podman process) spawns a `gvproxy` process on the host system. The `gvproxy` API is accessible on port 7777 on all IP addresses on the host. If that port is op
- affected < 2:1.10.1-2.module_el8.10.0+3909+6e1c1eb7fixed 2:1.10.1-2.module_el8.10.0+3909+6e1c1eb7
In Go before 1.15.13 and 1.16.x before 1.16.5, there can be a panic for a large exponent to the math/big.Rat SetString or UnmarshalText method.
- affected < 2:1.0.1-38.module_el8.9.0+3627+db8ec155fixed 2:1.0.1-38.module_el8.9.0+3627+db8ec155
runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. (This vul
Page 6 of 6