Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jhj6-5mh6-4pvf

Опубликовано: 24 мая 2021
Источник: github
Github: Прошло ревью
CVSS3: 5.9

Описание

Denial-of-Service within Docker container

Impact

If you run teler inside a Docker container and encounter errors.Exit function, it will cause denial-of-service (SIGSEGV) because it doesn't get process ID and process group ID of teler properly to kills.

Specific Go Packages Affected

ktbs.dev/teler/pkg/errors

Patches

Upgrade to the >= 0.0.1 version.

Workarounds

N/A

References

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

ktbs.dev/teler

go
Затронутые версииВерсия исправления

< 0.0.1

0.0.1

EPSS

Процентиль: 59%
0.0039
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-476

Связанные уязвимости

CVSS3: 5.9
nvd
больше 5 лет назад

In teler before version 0.0.1, if you run teler inside a Docker container and encounter `errors.Exit` function, it will cause denial-of-service (`SIGSEGV`) because it doesn't get process ID and process group ID of teler properly to kills. The issue is patched in teler 0.0.1 and 0.0.1-dev5.1.

EPSS

Процентиль: 59%
0.0039
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-476