VYPR

rpm package

almalinux/containers-common

pkg:rpm/almalinux/containers-common

Vulnerabilities (109)

  • CVE-2022-21698HigFeb 15, 2022
    affected < 2:1-27.module_el8.6.0+2878+e681bc44fixed 2:1-27.module_el8.6.0+2878+e681bc44

    client_golang is the instrumentation library for Go applications in Prometheus, and the promhttp package in client_golang provides tooling around HTTP servers and clients. In client_golang prior to version 1.11.1, HTTP server is susceptible to a Denial of Service through unbounde

  • CVE-2021-4024MedDec 23, 2021
    affected < 2:1-82.module_el8.10.0+3876+e55593a8fixed 2:1-82.module_el8.10.0+3876+e55593a8

    A flaw was found in podman. The `podman machine` function (used to create and manage Podman virtual machine containing a Podman process) spawns a `gvproxy` process on the host system. The `gvproxy` API is accessible on port 7777 on all IP addresses on the host. If that port is op

  • CVE-2021-33198HigAug 2, 2021
    affected < 2:1-82.module_el8.10.0+3876+e55593a8fixed 2:1-82.module_el8.10.0+3876+e55593a8

    In Go before 1.15.13 and 1.16.x before 1.16.5, there can be a panic for a large exponent to the math/big.Rat SetString or UnmarshalText method.

  • CVE-2021-30465HigMay 27, 2021
    affected < 1:0.1.41-4.module_el8.5.0+108+00865455fixed 1:0.1.41-4.module_el8.5.0+108+00865455

    runc before 1.0.0-rc95 allows a Container Filesystem Breakout via Directory Traversal. To exploit the vulnerability, an attacker must be able to create multiple containers with a fairly specific mount configuration. The problem occurs via a symlink-exchange attack that relies on

  • CVE-2021-20188HigFeb 11, 2021
    affected < 1:0.1.32-6.git1715c90.module_el8.4.0+2478+12421f43fixed 1:0.1.32-6.git1715c90.module_el8.4.0+2478+12421f43

    A flaw was found in podman before 1.7.0. File permissions for non-root users running in a privileged container are not correctly checked. This flaw can be abused by a low-privileged user inside the container to access any other file in the container, even if owned by the root use

  • CVE-2019-19921HigFeb 12, 2020
    affected < 2:1-38.module_el8.9.0+3627+db8ec155fixed 2:1-38.module_el8.9.0+3627+db8ec155

    runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. (This vul

  • CVE-2020-7039MedJan 16, 2020
    affected < 1:0.1.32-6.git1715c90.module_el8.4.0+2478+12421f43fixed 1:0.1.32-6.git1715c90.module_el8.4.0+2478+12421f43

    tcp_emu in tcp_subr.c in libslirp 4.1.0, as used in QEMU 4.2.0, mismanages memory, as demonstrated by IRC DCC commands in EMU_IRC. This can cause a heap-based buffer overflow or other out-of-bounds access which can lead to a DoS or potential execute arbitrary code.

  • CVE-2019-9514HigAug 13, 2019
    affected < 1:0.1.32-6.git1715c90.module_el8.4.0+2478+12421f43fixed 1:0.1.32-6.git1715c90.module_el8.4.0+2478+12421f43

    Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over each stream that should solicit a stream of RST_STREAM frames from the peer. Depending on how the peer

  • CVE-2019-9512HigAug 13, 2019
    affected < 1:0.1.32-6.git1715c90.module_el8.4.0+2478+12421f43fixed 1:0.1.32-6.git1715c90.module_el8.4.0+2478+12421f43

    Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of service. The attacker sends continual pings to an HTTP/2 peer, causing the peer to build an internal queue of responses. Depending on how efficiently this data is queued, this can consum

Page 6 of 6