Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2020-8945

Опубликовано: 12 фев. 2020
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 5.1
CVSS3: 7.5

Описание

The proglottis Go wrapper before 0.1.1 for the GPGME library has a use-after-free, as demonstrated by use for container image pulls by Docker or CRI-O. This leads to a crash or potential code execution during GPG signature verification.

РелизСтатусПримечание
bionic

DNE

devel

not-affected

0.1.1-1
eoan

ignored

end of life
esm-apps/focal

needs-triage

esm-apps/jammy

not-affected

0.1.1-1
esm-apps/noble

not-affected

0.1.1-1
esm-infra-legacy/trusty

DNE

focal

ignored

end of standard support, was needs-triage
groovy

not-affected

0.1.1-1
hirsute

not-affected

0.1.1-1

Показывать по

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
devel

needs-triage

eoan

ignored

end of life
esm-apps/bionic

needs-triage

esm-apps/noble

needs-triage

esm-infra-legacy/trusty

DNE

esm-infra/focal

DNE

focal

DNE

groovy

DNE

hirsute

DNE

Показывать по

EPSS

Процентиль: 88%
0.04013
Низкий

5.1 Medium

CVSS2

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
больше 5 лет назад

The proglottis Go wrapper before 0.1.1 for the GPGME library has a use-after-free, as demonstrated by use for container image pulls by Docker or CRI-O. This leads to a crash or potential code execution during GPG signature verification.

CVSS3: 7.5
nvd
больше 5 лет назад

The proglottis Go wrapper before 0.1.1 for the GPGME library has a use-after-free, as demonstrated by use for container image pulls by Docker or CRI-O. This leads to a crash or potential code execution during GPG signature verification.

CVSS3: 7.5
debian
больше 5 лет назад

The proglottis Go wrapper before 0.1.1 for the GPGME library has a use ...

CVSS3: 7.5
github
около 4 лет назад

GPGME Go wrapper contains Use After Free

oracle-oval
почти 5 лет назад

ELSA-2020-1230: skopeo security and bug fix update (MODERATE)

EPSS

Процентиль: 88%
0.04013
Низкий

5.1 Medium

CVSS2

7.5 High

CVSS3

Уязвимость CVE-2020-8945