Логотип exploitDog
bind:CVE-2021-20291
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-20291

Количество 13

Количество 13

ubuntu логотип

CVE-2021-20291

больше 4 лет назад

A deadlock vulnerability was found in 'github.com/containers/storage' in versions before 1.28.1. When a container image is processed, each layer is unpacked using `tar`. If one of those layers is not a valid `tar` archive this causes an error leading to an unexpected situation where the code indefinitely waits for the tar unpacked stream, which never finishes. An attacker could use this vulnerability to craft a malicious image, which when downloaded and stored by an application using containers/storage, would then cause a deadlock leading to a Denial of Service (DoS).

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2021-20291

больше 4 лет назад

A deadlock vulnerability was found in 'github.com/containers/storage' in versions before 1.28.1. When a container image is processed, each layer is unpacked using `tar`. If one of those layers is not a valid `tar` archive this causes an error leading to an unexpected situation where the code indefinitely waits for the tar unpacked stream, which never finishes. An attacker could use this vulnerability to craft a malicious image, which when downloaded and stored by an application using containers/storage, would then cause a deadlock leading to a Denial of Service (DoS).

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2021-20291

больше 4 лет назад

A deadlock vulnerability was found in 'github.com/containers/storage' in versions before 1.28.1. When a container image is processed, each layer is unpacked using `tar`. If one of those layers is not a valid `tar` archive this causes an error leading to an unexpected situation where the code indefinitely waits for the tar unpacked stream, which never finishes. An attacker could use this vulnerability to craft a malicious image, which when downloaded and stored by an application using containers/storage, would then cause a deadlock leading to a Denial of Service (DoS).

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2021-20291

больше 4 лет назад

A deadlock vulnerability was found in 'github.com/containers/storage' ...

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-7qw8-847f-pggm

больше 4 лет назад

Improper Locking in github.com/containers/storage

CVSS3: 6.5
EPSS: Низкий
rocky логотип

RLSA-2021:4154

почти 4 года назад

Moderate: container-tools:rhel8 security, bug fix, and enhancement update

EPSS: Низкий
oracle-oval логотип

ELSA-2022-7955

почти 3 года назад

ELSA-2022-7955: skopeo security and bug fix update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2021-4154

почти 4 года назад

ELSA-2021-4154: container-tools:ol8 security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:3312-1

около 3 лет назад

Security update for libcontainers-common

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2022:23018-1

больше 3 лет назад

Security update for conmon, libcontainers-common, libseccomp, podman

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:23018-1

больше 3 лет назад

Security update for conmon, libcontainers-common, libseccomp, podman

EPSS: Низкий
oracle-oval логотип

ELSA-2022-8008

почти 3 года назад

ELSA-2022-8008: buildah security and bug fix update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2022-7954

почти 3 года назад

ELSA-2022-7954: podman security and bug fix update (MODERATE)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2021-20291

A deadlock vulnerability was found in 'github.com/containers/storage' in versions before 1.28.1. When a container image is processed, each layer is unpacked using `tar`. If one of those layers is not a valid `tar` archive this causes an error leading to an unexpected situation where the code indefinitely waits for the tar unpacked stream, which never finishes. An attacker could use this vulnerability to craft a malicious image, which when downloaded and stored by an application using containers/storage, would then cause a deadlock leading to a Denial of Service (DoS).

CVSS3: 6.5
0%
Низкий
больше 4 лет назад
redhat логотип
CVE-2021-20291

A deadlock vulnerability was found in 'github.com/containers/storage' in versions before 1.28.1. When a container image is processed, each layer is unpacked using `tar`. If one of those layers is not a valid `tar` archive this causes an error leading to an unexpected situation where the code indefinitely waits for the tar unpacked stream, which never finishes. An attacker could use this vulnerability to craft a malicious image, which when downloaded and stored by an application using containers/storage, would then cause a deadlock leading to a Denial of Service (DoS).

CVSS3: 6.5
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-20291

A deadlock vulnerability was found in 'github.com/containers/storage' in versions before 1.28.1. When a container image is processed, each layer is unpacked using `tar`. If one of those layers is not a valid `tar` archive this causes an error leading to an unexpected situation where the code indefinitely waits for the tar unpacked stream, which never finishes. An attacker could use this vulnerability to craft a malicious image, which when downloaded and stored by an application using containers/storage, would then cause a deadlock leading to a Denial of Service (DoS).

CVSS3: 6.5
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-20291

A deadlock vulnerability was found in 'github.com/containers/storage' ...

CVSS3: 6.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-7qw8-847f-pggm

Improper Locking in github.com/containers/storage

CVSS3: 6.5
0%
Низкий
больше 4 лет назад
rocky логотип
RLSA-2021:4154

Moderate: container-tools:rhel8 security, bug fix, and enhancement update

почти 4 года назад
oracle-oval логотип
ELSA-2022-7955

ELSA-2022-7955: skopeo security and bug fix update (MODERATE)

почти 3 года назад
oracle-oval логотип
ELSA-2021-4154

ELSA-2021-4154: container-tools:ol8 security, bug fix, and enhancement update (MODERATE)

почти 4 года назад
suse-cvrf логотип
SUSE-SU-2022:3312-1

Security update for libcontainers-common

около 3 лет назад
suse-cvrf логотип
openSUSE-SU-2022:23018-1

Security update for conmon, libcontainers-common, libseccomp, podman

больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:23018-1

Security update for conmon, libcontainers-common, libseccomp, podman

больше 3 лет назад
oracle-oval логотип
ELSA-2022-8008

ELSA-2022-8008: buildah security and bug fix update (MODERATE)

почти 3 года назад
oracle-oval логотип
ELSA-2022-7954

ELSA-2022-7954: podman security and bug fix update (MODERATE)

почти 3 года назад

Уязвимостей на страницу