VYPR

rpm package

suse/amazon-ssm-agent&distro=SUSE Linux Enterprise Module for Public Cloud 12

pkg:rpm/suse/amazon-ssm-agent&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2012

Vulnerabilities (23)

  • CVE-2025-22869HigFeb 26, 2025
    affected < 3.3.4624.0-4.49.1fixed 3.3.4624.0-4.49.1

    SSH servers which implement file transfer protocols are vulnerable to a denial of service attack from clients which complete the key exchange slowly, or not at all, causing pending content to be read into memory, but never transmitted.

  • CVE-2025-21613CriJan 6, 2025
    affected < 3.3.1611.0-4.36.1fixed 3.3.1611.0-4.36.1

    go-git is a highly extensible git implementation library written in pure Go. An argument injection vulnerability was discovered in go-git versions prior to v5.13. Successful exploitation of this vulnerability could allow an attacker to set arbitrary values to git-upload-pack flag

  • CVE-2022-29527HigApr 20, 2022
    affected < 3.1.1260.0-4.27.2fixed 3.1.1260.0-4.27.2

    Amazon AWS amazon-ssm-agent before 3.1.1208.0 creates a world-writable sudoers file, which allows local attackers to inject Sudo rules and escalate privileges to root. This occurs in certain situations involving a race condition.

Page 2 of 2