VYPR

rpm package

suse/golang-github-prometheus-alertmanager&distro=SUSE Manager Client Tools 12

pkg:rpm/suse/golang-github-prometheus-alertmanager&distro=SUSE%20Manager%20Client%20Tools%2012

Vulnerabilities (43)

  • CVE-2021-3711Aug 24, 2021
    affected < 0.23.0-1.12.3fixed 0.23.0-1.12.3

    In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_decrypt(). Typically an application will call this function twice. The first time, on entry, the "out" parameter can be NULL and, on exit, the "outlen" parameter is populated with

  • CVE-2021-36222Jul 22, 2021
    affected < 0.23.0-1.12.3fixed 0.23.0-1.12.3

    ec_verify in kdc/kdc_preauth_ec.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.4 and 1.19.x before 1.19.2 allows remote attackers to cause a NULL pointer dereference and daemon crash. This occurs because a return value is not properly managed in a

  • CVE-2020-7753Oct 27, 2020
    affected < 0.26.0-1.24.2fixed 0.26.0-1.24.2

    All versions of package trim are vulnerable to Regular Expression Denial of Service (ReDoS) via trim().

Page 3 of 3