VYPR

rpm package

opensuse/cni&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/cni&distro=openSUSE%20Tumbleweed

Vulnerabilities (2)

  • CVE-2021-38561Dec 26, 2022
    affected < 1.1.2-2.1fixed 1.1.2-2.1

    golang.org/x/text/language in golang.org/x/text before 0.3.7 can panic with an out-of-bounds read during BCP 47 language tag parsing. Index calculation is mishandled. If parsing untrusted user input, this can be used as a vector for a denial-of-service attack.

  • CVE-2021-20206Mar 26, 2021
    affected < 1.0.1-3.1fixed 1.0.1-3.1

    An improper limitation of path name flaw was found in containernetworking/cni in versions before 0.8.1. When specifying the plugin to load in the 'type' field in the network configuration, it is possible to use special elements such as "../" separators to reference binaries elsew