Логотип exploitDog
bind:CVE-2023-25153
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-25153

Количество 10

Количество 10

ubuntu логотип

CVE-2023-25153

около 3 лет назад

containerd is an open source container runtime. Before versions 1.6.18 and 1.5.18, when importing an OCI image, there was no limit on the number of bytes read for certain files. A maliciously crafted image with a large file where a limit was not applied could cause a denial of service. This bug has been fixed in containerd 1.6.18 and 1.5.18. Users should update to these versions to resolve the issue. As a workaround, ensure that only trusted images are used and that only trusted users have permissions to import images.

CVSS3: 6.2
EPSS: Низкий
redhat логотип

CVE-2023-25153

около 3 лет назад

containerd is an open source container runtime. Before versions 1.6.18 and 1.5.18, when importing an OCI image, there was no limit on the number of bytes read for certain files. A maliciously crafted image with a large file where a limit was not applied could cause a denial of service. This bug has been fixed in containerd 1.6.18 and 1.5.18. Users should update to these versions to resolve the issue. As a workaround, ensure that only trusted images are used and that only trusted users have permissions to import images.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2023-25153

около 3 лет назад

containerd is an open source container runtime. Before versions 1.6.18 and 1.5.18, when importing an OCI image, there was no limit on the number of bytes read for certain files. A maliciously crafted image with a large file where a limit was not applied could cause a denial of service. This bug has been fixed in containerd 1.6.18 and 1.5.18. Users should update to these versions to resolve the issue. As a workaround, ensure that only trusted images are used and that only trusted users have permissions to import images.

CVSS3: 6.2
EPSS: Низкий
msrc логотип

CVE-2023-25153

около 3 лет назад

CVSS3: 5.5
EPSS: Низкий
debian логотип

CVE-2023-25153

около 3 лет назад

containerd is an open source container runtime. Before versions 1.6.18 ...

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-259w-8hf6-59c2

около 3 лет назад

OCI image importer memory exhaustion in github.com/containerd/containerd

CVSS3: 5.5
EPSS: Низкий
fstec логотип

BDU:2023-01489

около 3 лет назад

Уязвимость среды выполнения контейнеров Containerd, связанная с отсутствием ограничения на количество байтов, считываемых для определенных файлов, при импорте образов OCI, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 5.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:1827-1

почти 3 года назад

Security update for containerd

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:1826-1

почти 3 года назад

Security update for containerd

EPSS: Низкий
redos логотип

ROS-20230322-02

около 3 лет назад

Множественные уязвимости containerd

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2023-25153

containerd is an open source container runtime. Before versions 1.6.18 and 1.5.18, when importing an OCI image, there was no limit on the number of bytes read for certain files. A maliciously crafted image with a large file where a limit was not applied could cause a denial of service. This bug has been fixed in containerd 1.6.18 and 1.5.18. Users should update to these versions to resolve the issue. As a workaround, ensure that only trusted images are used and that only trusted users have permissions to import images.

CVSS3: 6.2
0%
Низкий
около 3 лет назад
redhat логотип
CVE-2023-25153

containerd is an open source container runtime. Before versions 1.6.18 and 1.5.18, when importing an OCI image, there was no limit on the number of bytes read for certain files. A maliciously crafted image with a large file where a limit was not applied could cause a denial of service. This bug has been fixed in containerd 1.6.18 and 1.5.18. Users should update to these versions to resolve the issue. As a workaround, ensure that only trusted images are used and that only trusted users have permissions to import images.

CVSS3: 5.5
0%
Низкий
около 3 лет назад
nvd логотип
CVE-2023-25153

containerd is an open source container runtime. Before versions 1.6.18 and 1.5.18, when importing an OCI image, there was no limit on the number of bytes read for certain files. A maliciously crafted image with a large file where a limit was not applied could cause a denial of service. This bug has been fixed in containerd 1.6.18 and 1.5.18. Users should update to these versions to resolve the issue. As a workaround, ensure that only trusted images are used and that only trusted users have permissions to import images.

CVSS3: 6.2
0%
Низкий
около 3 лет назад
msrc логотип
CVSS3: 5.5
0%
Низкий
около 3 лет назад
debian логотип
CVE-2023-25153

containerd is an open source container runtime. Before versions 1.6.18 ...

CVSS3: 6.2
0%
Низкий
около 3 лет назад
github логотип
GHSA-259w-8hf6-59c2

OCI image importer memory exhaustion in github.com/containerd/containerd

CVSS3: 5.5
0%
Низкий
около 3 лет назад
fstec логотип
BDU:2023-01489

Уязвимость среды выполнения контейнеров Containerd, связанная с отсутствием ограничения на количество байтов, считываемых для определенных файлов, при импорте образов OCI, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 5.5
0%
Низкий
около 3 лет назад
suse-cvrf логотип
SUSE-SU-2023:1827-1

Security update for containerd

почти 3 года назад
suse-cvrf логотип
SUSE-SU-2023:1826-1

Security update for containerd

почти 3 года назад
redos логотип
ROS-20230322-02

Множественные уязвимости containerd

CVSS3: 7.8
около 3 лет назад

Уязвимостей на страницу