rpm package
suse/container-suseconnect&distro=SUSE Enterprise Storage 7.1
pkg:rpm/suse/container-suseconnect&distro=SUSE%20Enterprise%20Storage%207.1
Vulnerabilities (8)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2024-24791 | Hig | 7.5 | < 2.5.0-150000.4.55.1 | 2.5.0-150000.4.55.1 | Jul 2, 2024 | The net/http HTTP/1.1 client mishandled the case where a server responds to a request with an "Expect: 100-continue" header with a non-informational (200 or higher) status. This mishandling could leave a client connection in an invalid state, where the next request sent on the co | |
| CVE-2024-24789 | — | < 2.5.0-150000.4.55.1 | 2.5.0-150000.4.55.1 | Jun 5, 2024 | The archive/zip package's handling of certain types of invalid zip files differs from the behavior of most zip implementations. This misalignment could be exploited to create an zip file with contents that vary depending on the implementation reading the file. The archive/zip pac | ||
| CVE-2024-24790 | — | < 2.5.0-150000.4.55.1 | 2.5.0-150000.4.55.1 | Jun 5, 2024 | The various Is methods (IsPrivate, IsLoopback, etc) did not work as expected for IPv4-mapped IPv6 addresses, returning false for addresses which would return true in their traditional IPv4 forms. | ||
| CVE-2023-24532 | — | < 2.4.0-150000.4.24.1 | 2.4.0-150000.4.24.1 | Mar 8, 2023 | The ScalarMult and ScalarBaseMult methods of the P256 Curve may return an incorrect result if called with some specific unreduced scalars (a scalar larger than the order of the curve). This does not impact usages of crypto/ecdsa or crypto/ecdh. | ||
| CVE-2022-41723 | — | < 2.4.0-150000.4.24.1 | 2.4.0-150000.4.24.1 | Feb 28, 2023 | A maliciously crafted HTTP/2 stream could cause excessive CPU consumption in the HPACK decoder, sufficient to cause a denial of service from a small number of small requests. | ||
| CVE-2022-41724 | — | < 2.4.0-150000.4.24.1 | 2.4.0-150000.4.24.1 | Feb 28, 2023 | Large handshake records may cause panics in crypto/tls. Both clients and servers may send large TLS handshake records which cause servers and clients, respectively, to panic when attempting to construct responses. This affects all TLS 1.3 clients, TLS 1.2 clients which explicitly | ||
| CVE-2022-41725 | — | < 2.4.0-150000.4.24.1 | 2.4.0-150000.4.24.1 | Feb 28, 2023 | A denial of service is possible from excessive resource consumption in net/http and mime/multipart. Multipart form parsing with mime/multipart.Reader.ReadForm can consume largely unlimited amounts of memory and disk files. This also affects form parsing in the net/http package wi | ||
| CVE-2022-41720 | — | < 2.4.0-150000.4.24.1 | 2.4.0-150000.4.24.1 | Dec 7, 2022 | On Windows, restricted files can be accessed via os.DirFS and http.Dir. The os.DirFS function and http.Dir type provide access to a tree of files rooted at a given directory. These functions permit access to Windows device files under that root. For example, os.DirFS("C:/tmp").Op |
- affected < 2.5.0-150000.4.55.1fixed 2.5.0-150000.4.55.1
The net/http HTTP/1.1 client mishandled the case where a server responds to a request with an "Expect: 100-continue" header with a non-informational (200 or higher) status. This mishandling could leave a client connection in an invalid state, where the next request sent on the co
- CVE-2024-24789Jun 5, 2024affected < 2.5.0-150000.4.55.1fixed 2.5.0-150000.4.55.1
The archive/zip package's handling of certain types of invalid zip files differs from the behavior of most zip implementations. This misalignment could be exploited to create an zip file with contents that vary depending on the implementation reading the file. The archive/zip pac
- CVE-2024-24790Jun 5, 2024affected < 2.5.0-150000.4.55.1fixed 2.5.0-150000.4.55.1
The various Is methods (IsPrivate, IsLoopback, etc) did not work as expected for IPv4-mapped IPv6 addresses, returning false for addresses which would return true in their traditional IPv4 forms.
- CVE-2023-24532Mar 8, 2023affected < 2.4.0-150000.4.24.1fixed 2.4.0-150000.4.24.1
The ScalarMult and ScalarBaseMult methods of the P256 Curve may return an incorrect result if called with some specific unreduced scalars (a scalar larger than the order of the curve). This does not impact usages of crypto/ecdsa or crypto/ecdh.
- CVE-2022-41723Feb 28, 2023affected < 2.4.0-150000.4.24.1fixed 2.4.0-150000.4.24.1
A maliciously crafted HTTP/2 stream could cause excessive CPU consumption in the HPACK decoder, sufficient to cause a denial of service from a small number of small requests.
- CVE-2022-41724Feb 28, 2023affected < 2.4.0-150000.4.24.1fixed 2.4.0-150000.4.24.1
Large handshake records may cause panics in crypto/tls. Both clients and servers may send large TLS handshake records which cause servers and clients, respectively, to panic when attempting to construct responses. This affects all TLS 1.3 clients, TLS 1.2 clients which explicitly
- CVE-2022-41725Feb 28, 2023affected < 2.4.0-150000.4.24.1fixed 2.4.0-150000.4.24.1
A denial of service is possible from excessive resource consumption in net/http and mime/multipart. Multipart form parsing with mime/multipart.Reader.ReadForm can consume largely unlimited amounts of memory and disk files. This also affects form parsing in the net/http package wi
- CVE-2022-41720Dec 7, 2022affected < 2.4.0-150000.4.24.1fixed 2.4.0-150000.4.24.1
On Windows, restricted files can be accessed via os.DirFS and http.Dir. The os.DirFS function and http.Dir type provide access to a tree of files rooted at a given directory. These functions permit access to Windows device files under that root. For example, os.DirFS("C:/tmp").Op