VYPR

rpm package

almalinux/grafana-pcp

pkg:rpm/almalinux/grafana-pcp

Vulnerabilities (25)

  • CVE-2022-30635HigAug 10, 2022
    affected < 3.2.0-2.el8fixed 3.2.0-2.el8

    Uncontrolled recursion in Decoder.Decode in encoding/gob before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a message which contains deeply nested structures.

  • CVE-2022-30632HigAug 10, 2022
    affected < 3.2.0-2.el8fixed 3.2.0-2.el8

    Uncontrolled recursion in Glob in path/filepath before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a path containing a large number of path separators.

  • CVE-2022-30631HigAug 10, 2022
    affected < 3.2.0-2.el8fixed 3.2.0-2.el8

    Uncontrolled recursion in Reader.Read in compress/gzip before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via an archive containing a large number of concatenated 0-length compressed files.

  • CVE-2022-30630HigAug 10, 2022
    affected < 3.2.0-2.el8fixed 3.2.0-2.el8

    Uncontrolled recursion in Glob in io/fs before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a path which contains a large number of path separators.

  • CVE-2022-1705MedAug 10, 2022
    affected < 3.2.0-2.el8fixed 3.2.0-2.el8

    Acceptance of some invalid Transfer-Encoding headers in the HTTP/1 client in net/http before Go 1.17.12 and Go 1.18.4 allows HTTP request smuggling if combined with an intermediate server that also improperly fails to reject the header as invalid.

Page 2 of 2