VYPR

rpm package

suse/skopeo&distro=SUSE Linux Enterprise Module for Basesystem 15 SP5

pkg:rpm/suse/skopeo&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP5

Vulnerabilities (2)

  • CVE-2024-3727HigMay 14, 2024
    affected < 1.14.4-150300.11.11.1fixed 1.14.4-150300.11.11.1

    A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks.

  • CVE-2024-28180Mar 9, 2024
    affected < 1.14.4-150300.11.11.1fixed 1.14.4-150300.11.11.1

    Package jose aims to provide an implementation of the Javascript Object Signing and Encryption set of standards. An attacker could send a JWE containing compressed data that used large amounts of memory and CPU when decompressed by Decrypt or DecryptMulti. Those functions now ret