Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-29482

Опубликовано: 19 авг. 2020
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

xz is a compression and decompression library focusing on the xz format completely written in Go. The function readUvarint used to read the xz container format may not terminate a loop provide malicous input. The problem has been fixed in release v0.5.8. As a workaround users can limit the size of the compressed file input to a reasonable size for their use case. The standard library had recently the same issue and got the CVE-2020-16845 allocated.

A flaw was found in github.com/ulikunitz/xz. The function readUvarint may not terminate a loop what could lead to denial of service (DoS).

Отчет

In OpenShift Container Platform (OCP), OpenShift ServiceMesh (OSSM) and Red Hat Advanced Cluster Management for Kubernetes (RHACM) the affected components are behind OpenShift OAuth authentication, therefore the impact is low. In OCP before 4.7 the buildah, skopeo and podman packages include vulnerable version of github.com/ulikunitz/xz, but these OCP releases are already in the Maintenance Phase of the support, hence affected components are marked as wontfix. This may be fixed in the future.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Migration Toolkit for Containersopenshift-migration-plugin-containerAffected
Migration Toolkit for Containersrhmtc/openshift-migration-controller-rhel8Not affected
Red Hat Advanced Cluster Management for Kubernetes 2multicloud-operators-application-containerAffected
Red Hat Advanced Cluster Management for Kubernetes 2multicloud-operators-channel-containerWill not fix
Red Hat Advanced Cluster Management for Kubernetes 2multicloud-operators-subscriptionNot affected
Red Hat Advanced Cluster Management for Kubernetes 2multicloud-operators-subscription-releaseNot affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/clusterlifecycle-state-metrics-rhel8Not affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/openshift-hive-rhel8Fix deferred
Red Hat OpenShift Container Platform 4buildahWill not fix
Red Hat OpenShift Container Platform 4cri-oNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-835->CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1954368ulikunitz/xz: Infinite loop in readUvarint allows for denial of service

EPSS

Процентиль: 62%
0.00435
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 4 лет назад

xz is a compression and decompression library focusing on the xz format completely written in Go. The function readUvarint used to read the xz container format may not terminate a loop provide malicous input. The problem has been fixed in release v0.5.8. As a workaround users can limit the size of the compressed file input to a reasonable size for their use case. The standard library had recently the same issue and got the CVE-2020-16845 allocated.

CVSS3: 7.5
nvd
больше 4 лет назад

xz is a compression and decompression library focusing on the xz format completely written in Go. The function readUvarint used to read the xz container format may not terminate a loop provide malicous input. The problem has been fixed in release v0.5.8. As a workaround users can limit the size of the compressed file input to a reasonable size for their use case. The standard library had recently the same issue and got the CVE-2020-16845 allocated.

CVSS3: 7.5
debian
больше 4 лет назад

xz is a compression and decompression library focusing on the xz forma ...

CVSS3: 7.5
github
больше 4 лет назад

github.com/ulikunitz/xz fixes readUvarint Denial of Service (DoS)

EPSS

Процентиль: 62%
0.00435
Низкий

7.5 High

CVSS3

Уязвимость CVE-2021-29482