Логотип exploitDog
bind:"CVE-2023-39326" OR bind:"CVE-2023-45287" OR bind:"CVE-2024-21626"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2023-39326" OR bind:"CVE-2023-45287" OR bind:"CVE-2024-21626"

Количество 58

Количество 58

oracle-oval логотип

ELSA-2024-12190

почти 2 года назад

ELSA-2024-12190: conmon security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-12189

почти 2 года назад

ELSA-2024-12189: conmon security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-1149

почти 2 года назад

ELSA-2024-1149: skopeo security update (MODERATE)

EPSS: Низкий
fstec логотип

BDU:2024-00175

около 2 лет назад

Уязвимость пакета net/http языка программирования Go, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 5.3
EPSS: Низкий
oracle-oval логотип

ELSA-2024-1131

почти 2 года назад

ELSA-2024-1131: golang security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-0887

почти 2 года назад

ELSA-2024-0887: go-toolset:ol8 security update (MODERATE)

EPSS: Низкий
ubuntu логотип

CVE-2023-45287

около 2 лет назад

Before Go 1.20, the RSA based TLS key exchanges used the math/big library, which is not constant time. RSA blinding was applied to prevent timing attacks, but analysis shows this may not have been fully effective. In particular it appears as if the removal of PKCS#1 padding may leak timing information, which in turn could be used to recover session key bits. In Go 1.20, the crypto/tls library switched to a fully constant time RSA implementation, which we do not believe exhibits any timing side channels.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2023-45287

около 2 лет назад

Before Go 1.20, the RSA based TLS key exchanges used the math/big library, which is not constant time. RSA blinding was applied to prevent timing attacks, but analysis shows this may not have been fully effective. In particular it appears as if the removal of PKCS#1 padding may leak timing information, which in turn could be used to recover session key bits. In Go 1.20, the crypto/tls library switched to a fully constant time RSA implementation, which we do not believe exhibits any timing side channels.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2023-45287

около 2 лет назад

Before Go 1.20, the RSA based TLS key exchanges used the math/big library, which is not constant time. RSA blinding was applied to prevent timing attacks, but analysis shows this may not have been fully effective. In particular it appears as if the removal of PKCS#1 padding may leak timing information, which in turn could be used to recover session key bits. In Go 1.20, the crypto/tls library switched to a fully constant time RSA implementation, which we do not believe exhibits any timing side channels.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2023-45287

5 месяцев назад

Before Go 1.20, the RSA based key exchange methods in crypto/tls may exhibit a timing side channel

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2023-45287

около 2 лет назад

Before Go 1.20, the RSA based TLS key exchanges used the math/big libr ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2024-21626

около 2 лет назад

runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc 1.1.11 and earlier, due to an internal file descriptor leak, an attacker could cause a newly-spawned container process (from runc exec) to have a working directory in the host filesystem namespace, allowing for a container escape by giving access to the host filesystem ("attack 2"). The same attack could be used by a malicious image to allow a container process to gain access to the host filesystem through runc run ("attack 1"). Variants of attacks 1 and 2 could be also be used to overwrite semi-arbitrary host binaries, allowing for complete container escapes ("attack 3a" and "attack 3b"). runc 1.1.12 includes patches for this issue.

CVSS3: 8.6
EPSS: Низкий
redhat логотип

CVE-2024-21626

около 2 лет назад

runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc 1.1.11 and earlier, due to an internal file descriptor leak, an attacker could cause a newly-spawned container process (from runc exec) to have a working directory in the host filesystem namespace, allowing for a container escape by giving access to the host filesystem ("attack 2"). The same attack could be used by a malicious image to allow a container process to gain access to the host filesystem through runc run ("attack 1"). Variants of attacks 1 and 2 could be also be used to overwrite semi-arbitrary host binaries, allowing for complete container escapes ("attack 3a" and "attack 3b"). runc 1.1.12 includes patches for this issue.

CVSS3: 8.6
EPSS: Низкий
nvd логотип

CVE-2024-21626

около 2 лет назад

runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc 1.1.11 and earlier, due to an internal file descriptor leak, an attacker could cause a newly-spawned container process (from runc exec) to have a working directory in the host filesystem namespace, allowing for a container escape by giving access to the host filesystem ("attack 2"). The same attack could be used by a malicious image to allow a container process to gain access to the host filesystem through runc run ("attack 1"). Variants of attacks 1 and 2 could be also be used to overwrite semi-arbitrary host binaries, allowing for complete container escapes ("attack 3a" and "attack 3b"). runc 1.1.12 includes patches for this issue.

CVSS3: 8.6
EPSS: Низкий
msrc логотип

CVE-2024-21626

почти 2 года назад

GitHub: CVE-2024-21626 Container breakout through process.cwd trickery and leaked fds

EPSS: Низкий
debian логотип

CVE-2024-21626

около 2 лет назад

runc is a CLI tool for spawning and running containers on Linux accord ...

CVSS3: 8.6
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:4931-1

около 2 лет назад

Security update for go1.21-openssl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:4930-1

около 2 лет назад

Security update for go1.20-openssl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:4709-1

около 2 лет назад

Security update for go1.21

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:4708-1

около 2 лет назад

Security update for go1.20

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2024-12190

ELSA-2024-12190: conmon security update (IMPORTANT)

почти 2 года назад
oracle-oval логотип
ELSA-2024-12189

ELSA-2024-12189: conmon security update (IMPORTANT)

почти 2 года назад
oracle-oval логотип
ELSA-2024-1149

ELSA-2024-1149: skopeo security update (MODERATE)

почти 2 года назад
fstec логотип
BDU:2024-00175

Уязвимость пакета net/http языка программирования Go, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 5.3
0%
Низкий
около 2 лет назад
oracle-oval логотип
ELSA-2024-1131

ELSA-2024-1131: golang security update (MODERATE)

почти 2 года назад
oracle-oval логотип
ELSA-2024-0887

ELSA-2024-0887: go-toolset:ol8 security update (MODERATE)

почти 2 года назад
ubuntu логотип
CVE-2023-45287

Before Go 1.20, the RSA based TLS key exchanges used the math/big library, which is not constant time. RSA blinding was applied to prevent timing attacks, but analysis shows this may not have been fully effective. In particular it appears as if the removal of PKCS#1 padding may leak timing information, which in turn could be used to recover session key bits. In Go 1.20, the crypto/tls library switched to a fully constant time RSA implementation, which we do not believe exhibits any timing side channels.

CVSS3: 7.5
0%
Низкий
около 2 лет назад
redhat логотип
CVE-2023-45287

Before Go 1.20, the RSA based TLS key exchanges used the math/big library, which is not constant time. RSA blinding was applied to prevent timing attacks, but analysis shows this may not have been fully effective. In particular it appears as if the removal of PKCS#1 padding may leak timing information, which in turn could be used to recover session key bits. In Go 1.20, the crypto/tls library switched to a fully constant time RSA implementation, which we do not believe exhibits any timing side channels.

CVSS3: 7.5
0%
Низкий
около 2 лет назад
nvd логотип
CVE-2023-45287

Before Go 1.20, the RSA based TLS key exchanges used the math/big library, which is not constant time. RSA blinding was applied to prevent timing attacks, but analysis shows this may not have been fully effective. In particular it appears as if the removal of PKCS#1 padding may leak timing information, which in turn could be used to recover session key bits. In Go 1.20, the crypto/tls library switched to a fully constant time RSA implementation, which we do not believe exhibits any timing side channels.

CVSS3: 7.5
0%
Низкий
около 2 лет назад
msrc логотип
CVE-2023-45287

Before Go 1.20, the RSA based key exchange methods in crypto/tls may exhibit a timing side channel

CVSS3: 7.5
0%
Низкий
5 месяцев назад
debian логотип
CVE-2023-45287

Before Go 1.20, the RSA based TLS key exchanges used the math/big libr ...

CVSS3: 7.5
0%
Низкий
около 2 лет назад
ubuntu логотип
CVE-2024-21626

runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc 1.1.11 and earlier, due to an internal file descriptor leak, an attacker could cause a newly-spawned container process (from runc exec) to have a working directory in the host filesystem namespace, allowing for a container escape by giving access to the host filesystem ("attack 2"). The same attack could be used by a malicious image to allow a container process to gain access to the host filesystem through runc run ("attack 1"). Variants of attacks 1 and 2 could be also be used to overwrite semi-arbitrary host binaries, allowing for complete container escapes ("attack 3a" and "attack 3b"). runc 1.1.12 includes patches for this issue.

CVSS3: 8.6
4%
Низкий
около 2 лет назад
redhat логотип
CVE-2024-21626

runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc 1.1.11 and earlier, due to an internal file descriptor leak, an attacker could cause a newly-spawned container process (from runc exec) to have a working directory in the host filesystem namespace, allowing for a container escape by giving access to the host filesystem ("attack 2"). The same attack could be used by a malicious image to allow a container process to gain access to the host filesystem through runc run ("attack 1"). Variants of attacks 1 and 2 could be also be used to overwrite semi-arbitrary host binaries, allowing for complete container escapes ("attack 3a" and "attack 3b"). runc 1.1.12 includes patches for this issue.

CVSS3: 8.6
4%
Низкий
около 2 лет назад
nvd логотип
CVE-2024-21626

runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc 1.1.11 and earlier, due to an internal file descriptor leak, an attacker could cause a newly-spawned container process (from runc exec) to have a working directory in the host filesystem namespace, allowing for a container escape by giving access to the host filesystem ("attack 2"). The same attack could be used by a malicious image to allow a container process to gain access to the host filesystem through runc run ("attack 1"). Variants of attacks 1 and 2 could be also be used to overwrite semi-arbitrary host binaries, allowing for complete container escapes ("attack 3a" and "attack 3b"). runc 1.1.12 includes patches for this issue.

CVSS3: 8.6
4%
Низкий
около 2 лет назад
msrc логотип
CVE-2024-21626

GitHub: CVE-2024-21626 Container breakout through process.cwd trickery and leaked fds

4%
Низкий
почти 2 года назад
debian логотип
CVE-2024-21626

runc is a CLI tool for spawning and running containers on Linux accord ...

CVSS3: 8.6
4%
Низкий
около 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:4931-1

Security update for go1.21-openssl

около 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:4930-1

Security update for go1.20-openssl

около 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:4709-1

Security update for go1.21

около 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:4708-1

Security update for go1.20

около 2 лет назад

Уязвимостей на страницу