VYPR

rpm package

opensuse/oras&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/oras&distro=openSUSE%20Tumbleweed

Vulnerabilities (2)

  • CVE-2026-50163HigJul 17, 2026
    affected < 1.3.3-2.1fixed 1.3.3-2.1

    oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, ensureLinkPath in content/file/utils.go:262-275 validates a hardlink target relative to the extract base but returns the unresolved target, causing os.Link("victim.secret", "<extract_base>/payload.tar.gz/evil_cwd

  • CVE-2024-24790CriJun 5, 2024
    affected < 1.2.1-1.1fixed 1.2.1-1.1

    The various Is methods (IsPrivate, IsLoopback, etc) did not work as expected for IPv4-mapped IPv6 addresses, returning false for addresses which would return true in their traditional IPv4 forms.