VYPR

rpm package

almalinux/slirp4netns

pkg:rpm/almalinux/slirp4netns

Vulnerabilities (114)

  • CVE-2022-21698HigFeb 15, 2022
    affected < 1.1.8-2.module_el8.6.0+2877+8e437bf5fixed 1.1.8-2.module_el8.6.0+2877+8e437bf5

    client_golang is the instrumentation library for Go applications in Prometheus, and the promhttp package in client_golang provides tooling around HTTP servers and clients. In client_golang prior to version 1.11.1, HTTP server is susceptible to a Denial of Service through unbounde

  • CVE-2021-4024MedDec 23, 2021
    affected < 1.2.3-1.module_el8.10.0+3845+87b84552fixed 1.2.3-1.module_el8.10.0+3845+87b84552

    A flaw was found in podman. The `podman machine` function (used to create and manage Podman virtual machine containing a Podman process) spawns a `gvproxy` process on the host system. The `gvproxy` API is accessible on port 7777 on all IP addresses on the host. If that port is op

  • CVE-2021-33198HigAug 2, 2021
    affected < 1.2.3-1.module_el8.10.0+3845+87b84552fixed 1.2.3-1.module_el8.10.0+3845+87b84552

    In Go before 1.15.13 and 1.16.x before 1.16.5, there can be a panic for a large exponent to the math/big.Rat SetString or UnmarshalText method.

  • CVE-2020-1702LowMay 27, 2021
    affected < 0.4.2-3.git21fdece.module_el8.5.0+2635+e4386a39fixed 0.4.2-3.git21fdece.module_el8.5.0+2635+e4386a39

    A malicious container image can consume an unbounded amount of memory when being pulled to a container runtime host, such as Red Hat Enterprise Linux using podman, or OpenShift Container Platform. An attacker can use this flaw to trick a user, with privileges to pull container im

  • CVE-2021-30465HigMay 27, 2021
    affected < 0.4.2-3.git21fdece.module_el8.5.0+2635+e4386a39fixed 0.4.2-3.git21fdece.module_el8.5.0+2635+e4386a39

    runc before 1.0.0-rc95 allows a Container Filesystem Breakout via Directory Traversal. To exploit the vulnerability, an attacker must be able to create multiple containers with a fairly specific mount configuration. The problem occurs via a symlink-exchange attack that relies on

  • CVE-2021-20291MedApr 1, 2021
    affected < 1.1.8-1.module_el8.6.0+2876+9ed4eae2fixed 1.1.8-1.module_el8.6.0+2876+9ed4eae2

    A deadlock vulnerability was found in 'github.com/containers/storage' in versions before 1.28.1. When a container image is processed, each layer is unpacked using `tar`. If one of those layers is not a valid `tar` archive this causes an error leading to an unexpected situation wh

  • CVE-2021-20188HigFeb 11, 2021
    affected < 0.1-5.dev.gitc4e1bc5.module_el8.3.0+2044+12421f43fixed 0.1-5.dev.gitc4e1bc5.module_el8.3.0+2044+12421f43

    A flaw was found in podman before 1.7.0. File permissions for non-root users running in a privileged container are not correctly checked. This flaw can be abused by a low-privileged user inside the container to access any other file in the container, even if owned by the root use

  • CVE-2021-20199MedFeb 2, 2021
    affected < 1.1.8-1.module_el8.6.0+2876+9ed4eae2fixed 1.1.8-1.module_el8.6.0+2876+9ed4eae2

    Rootless containers run with Podman, receive all traffic with a source IP address of 127.0.0.1 (including from remote hosts). This impacts containerized applications that trust localhost (127.0.01) connections by default and do not require authentication. This issue affects Podma

  • CVE-2020-29652HigDec 17, 2020
    affected < 1.1.8-1.module_el8.6.0+2876+9ed4eae2fixed 1.1.8-1.module_el8.6.0+2876+9ed4eae2

    A nil pointer dereference in the golang.org/x/crypto/ssh component through v0.0.0-20201203163018-be400aefbc4c for Go allows remote attackers to cause a denial of service against SSH servers.

  • CVE-2020-14370MedSep 23, 2020
    affected < 1.1.8-1.module_el8.6.0+2876+9ed4eae2fixed 1.1.8-1.module_el8.6.0+2876+9ed4eae2

    An information disclosure vulnerability was found in containers/podman in versions before 2.0.5. When using the deprecated Varlink API or the Docker-compatible REST API, if multiple containers are created in a short duration, the environment variables from the first container wil

  • CVE-2020-10696HigMar 31, 2020
    affected < 0.1-5.dev.gitc4e1bc5.module_el8.3.0+2044+12421f43fixed 0.1-5.dev.gitc4e1bc5.module_el8.3.0+2044+12421f43

    A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker to trick a user into building a malicious container image hosted on an HTTP(s) server and then write files to the user's system anywhere that the user has permissions.

  • CVE-2019-19921HigFeb 12, 2020
    affected < 0.4.2-3.git21fdece.module_el8.5.0+2635+e4386a39fixed 0.4.2-3.git21fdece.module_el8.5.0+2635+e4386a39

    runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. (This vul

  • CVE-2020-1726MedFeb 11, 2020
    affected < 0.4.2-3.git21fdece.module_el8.5.0+2635+e4386a39fixed 0.4.2-3.git21fdece.module_el8.5.0+2635+e4386a39

    A flaw was discovered in Podman where it incorrectly allows containers when created to overwrite existing files in volumes, even if they are mounted as read-only. When a user runs a malicious container or a container based on a malicious image with an attached volume that is used

  • CVE-2020-8608MedFeb 6, 2020
    affected < 0.4.2-3.git21fdece.module_el8.5.0+2635+e4386a39fixed 0.4.2-3.git21fdece.module_el8.5.0+2635+e4386a39

    In libslirp 4.1.0, as used in QEMU 4.2.0, tcp_subr.c misuses snprintf return values, leading to a buffer overflow in later code.

Page 6 of 6