Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2022:7959

Опубликовано: 15 нояб. 2022
Источник: rocky
Оценка: Low

Описание

Low: guestfs-tools security, bug fix, and enhancement update

guestfs-tools is a set of tools that can be used to make batch configuration changes to guests, get disk used/free statistics, perform backups and guest clones, change registry/UUID/hostname info, build guests from scratch, and much more.

Security Fix(es):

  • libguestfs: Buffer overflow in get_keys leads to DoS (CVE-2022-2211)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Rocky Linux 9.1 Release Notes linked from the References section.

Затронутые продукты

  • Rocky Linux 9

НаименованиеАрхитектураРелизRPM
guestfs-toolsx86_645.el9guestfs-tools-1.48.2-5.el9.x86_64.rpm
virt-win-regnoarch5.el9virt-win-reg-1.48.2-5.el9.noarch.rpm

Показывать по

Связанные CVE

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 3 года назад

A vulnerability was found in libguestfs. This issue occurs while calculating the greatest possible number of matching keys in the get_keys() function. This flaw leads to a denial of service, either by mistake or malicious actor.

CVSS3: 5.5
redhat
почти 3 года назад

A vulnerability was found in libguestfs. This issue occurs while calculating the greatest possible number of matching keys in the get_keys() function. This flaw leads to a denial of service, either by mistake or malicious actor.

CVSS3: 6.5
nvd
почти 3 года назад

A vulnerability was found in libguestfs. This issue occurs while calculating the greatest possible number of matching keys in the get_keys() function. This flaw leads to a denial of service, either by mistake or malicious actor.

CVSS3: 6.5
debian
почти 3 года назад

A vulnerability was found in libguestfs. This issue occurs while calcu ...

suse-cvrf
больше 2 лет назад

Security update for virt-v2v