Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m6wg-2mwg-4rfq

Опубликовано: 18 мая 2021
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

GPGME Go wrapper contains Use After Free

The proglottis Go wrapper before 0.1.1 for the GPGME library has a use-after-free, as demonstrated by use for container image pulls by Docker or CRI-O. This leads to a crash or potential code execution during GPG signature verification.

Пакеты

Наименование

github.com/proglottis/gpgme

go
Затронутые версииВерсия исправления

< 0.1.1

0.1.1

EPSS

Процентиль: 88%
0.04013
Низкий

7.5 High

CVSS3

Дефекты

CWE-416

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 5 лет назад

The proglottis Go wrapper before 0.1.1 for the GPGME library has a use-after-free, as demonstrated by use for container image pulls by Docker or CRI-O. This leads to a crash or potential code execution during GPG signature verification.

CVSS3: 7.5
redhat
больше 5 лет назад

The proglottis Go wrapper before 0.1.1 for the GPGME library has a use-after-free, as demonstrated by use for container image pulls by Docker or CRI-O. This leads to a crash or potential code execution during GPG signature verification.

CVSS3: 7.5
nvd
больше 5 лет назад

The proglottis Go wrapper before 0.1.1 for the GPGME library has a use-after-free, as demonstrated by use for container image pulls by Docker or CRI-O. This leads to a crash or potential code execution during GPG signature verification.

CVSS3: 7.5
debian
больше 5 лет назад

The proglottis Go wrapper before 0.1.1 for the GPGME library has a use ...

oracle-oval
почти 5 лет назад

ELSA-2020-1230: skopeo security and bug fix update (MODERATE)

EPSS

Процентиль: 88%
0.04013
Низкий

7.5 High

CVSS3

Дефекты

CWE-416