VYPR

rpm package

opensuse/containerd&distro=openSUSE Leap Micro 5.3

pkg:rpm/opensuse/containerd&distro=openSUSE%20Leap%20Micro%205.3

Vulnerabilities (6)

  • CVE-2023-45288HigApr 4, 2024
    affected < 1.7.17-150000.111.3fixed 1.7.17-150000.111.3

    An attacker may cause an HTTP/2 endpoint to read arbitrary amounts of header data by sending an excessive number of CONTINUATION frames. Maintaining HPACK state requires parsing and processing all HEADERS and CONTINUATION frames on a connection. When a request's headers exceed Ma

  • CVE-2023-25173Feb 16, 2023
    affected < 1.6.19-150000.87.1fixed 1.6.19-150000.87.1

    containerd is an open source container runtime. A bug was found in containerd prior to versions 1.6.18 and 1.5.18 where supplementary groups are not set up properly inside a container. If an attacker has direct access to a container and manipulates their supplementary group acces

  • CVE-2023-25153Feb 16, 2023
    affected < 1.6.19-150000.87.1fixed 1.6.19-150000.87.1

    containerd is an open source container runtime. Before versions 1.6.18 and 1.5.18, when importing an OCI image, there was no limit on the number of bytes read for certain files. A maliciously crafted image with a large file where a limit was not applied could cause a denial of se

  • CVE-2022-23471Dec 7, 2022
    affected < 1.6.12-150000.79.1fixed 1.6.12-150000.79.1

    containerd is an open source container runtime. A bug was found in containerd's CRI implementation where a user can exhaust memory on the host. In the CRI stream server, a goroutine is launched to handle terminal resize events if a TTY is requested. If the user's process fails to

  • CVE-2022-1996Jun 6, 2022
    affected < 1.7.8-150000.103.1fixed 1.7.8-150000.103.1

    Authorization Bypass Through User-Controlled Key in GitHub repository emicklei/go-restful prior to v3.8.0.

  • CVE-2022-27191Mar 18, 2022
    affected < 1.6.12-150000.79.1fixed 1.6.12-150000.79.1

    The golang.org/x/crypto/ssh package before 0.0.0-20220314234659-1baeb1ce4c0b for Go allows an attacker to crash a server in certain circumstances involving AddHostKey.