rpm package
suse/containerd&distro=SUSE Linux Enterprise Module for Containers 12
pkg:rpm/suse/containerd&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Containers%2012
Vulnerabilities (44)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2017-14992 | Med | 6.5 | < 0.2.9+gitr706_06b9cb351610-16.8.1 | 0.2.9+gitr706_06b9cb351610-16.8.1 | Nov 1, 2017 | Lack of content verification in Docker-CE (Also known as Moby) versions 1.12.6-0, 1.10.3, 17.03.0, 17.03.1, 17.03.2, 17.06.0, 17.06.1, 17.06.2, 17.09.0, and earlier allows a remote attacker to cause a Denial of Service via a crafted image layer payload, aka gzip bombing. | |
| CVE-2017-8932 | Med | 5.9 | < 0.2.5+gitr639_422e31c-20.2 | 0.2.5+gitr639_422e31c-20.2 | Jul 6, 2017 | A bug in the standard library ScalarMult implementation of curve P-256 for amd64 architectures in Go before 1.7.6 and 1.8.x before 1.8.2 causes incorrect results to be generated for specific input points. An adaptive attack can be mounted to progressively extract the scalar input | |
| CVE-2016-9962 | Med | 6.4 | < 0.2.5+gitr569_2a5e70c-15.3 | 0.2.5+gitr569_2a5e70c-15.3 | Jan 31, 2017 | RunC allowed additional container processes via 'runc exec' to be ptraced by the pid 1 of the container. This allows the main processes of the container, if running as root, to gain access to file-descriptors of these new processes during the initialization and can lead to conta | |
| CVE-2016-8867 | Hig | 7.5 | < 0.2.4+gitr565_0366d7e-9.1 | 0.2.4+gitr565_0366d7e-9.1 | Oct 28, 2016 | Docker Engine 1.12.2 enabled ambient capabilities with misconfigured capability policies. This allowed malicious images to bypass user permissions to access files within the container filesystem or mounted volumes. |
- affected < 0.2.9+gitr706_06b9cb351610-16.8.1fixed 0.2.9+gitr706_06b9cb351610-16.8.1
Lack of content verification in Docker-CE (Also known as Moby) versions 1.12.6-0, 1.10.3, 17.03.0, 17.03.1, 17.03.2, 17.06.0, 17.06.1, 17.06.2, 17.09.0, and earlier allows a remote attacker to cause a Denial of Service via a crafted image layer payload, aka gzip bombing.
- affected < 0.2.5+gitr639_422e31c-20.2fixed 0.2.5+gitr639_422e31c-20.2
A bug in the standard library ScalarMult implementation of curve P-256 for amd64 architectures in Go before 1.7.6 and 1.8.x before 1.8.2 causes incorrect results to be generated for specific input points. An adaptive attack can be mounted to progressively extract the scalar input
- affected < 0.2.5+gitr569_2a5e70c-15.3fixed 0.2.5+gitr569_2a5e70c-15.3
RunC allowed additional container processes via 'runc exec' to be ptraced by the pid 1 of the container. This allows the main processes of the container, if running as root, to gain access to file-descriptors of these new processes during the initialization and can lead to conta
- affected < 0.2.4+gitr565_0366d7e-9.1fixed 0.2.4+gitr565_0366d7e-9.1
Docker Engine 1.12.2 enabled ambient capabilities with misconfigured capability policies. This allowed malicious images to bypass user permissions to access files within the container filesystem or mounted volumes.
Page 3 of 3