Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-8945

Опубликовано: 12 фев. 2020
Источник: debian
EPSS Низкий

Описание

The proglottis Go wrapper before 0.1.1 for the GPGME library has a use-after-free, as demonstrated by use for container image pulls by Docker or CRI-O. This leads to a crash or potential code execution during GPG signature verification.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
golang-github-proglottis-gpgmefixed0.1.1-1package
golang-github-proglottis-gpgmepostponedbusterpackage

Примечания

  • https://github.com/proglottis/gpgme/pull/23

EPSS

Процентиль: 86%
0.02961
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 6 лет назад

The proglottis Go wrapper before 0.1.1 for the GPGME library has a use-after-free, as demonstrated by use for container image pulls by Docker or CRI-O. This leads to a crash or potential code execution during GPG signature verification.

CVSS3: 7.5
redhat
почти 6 лет назад

The proglottis Go wrapper before 0.1.1 for the GPGME library has a use-after-free, as demonstrated by use for container image pulls by Docker or CRI-O. This leads to a crash or potential code execution during GPG signature verification.

CVSS3: 7.5
nvd
почти 6 лет назад

The proglottis Go wrapper before 0.1.1 for the GPGME library has a use-after-free, as demonstrated by use for container image pulls by Docker or CRI-O. This leads to a crash or potential code execution during GPG signature verification.

CVSS3: 7.5
github
больше 4 лет назад

GPGME Go wrapper contains Use After Free

oracle-oval
больше 5 лет назад

ELSA-2020-1230: skopeo security and bug fix update (MODERATE)

EPSS

Процентиль: 86%
0.02961
Низкий