The proglottis Go wrapper before 0.1.1 for the GPGME library has a use-after-free, as demonstrated by use for container image pulls by Docker or CRI-O. This leads to a crash or potential code execution during GPG signature verification.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade docker-clientUpgrade docker-v1.10-migratorUpgrade buildah-debuginfoUpgrade containers-commonUpgrade dockerUpgrade podmanUpgrade skopeoUpgrade podman-debuginfoUpgrade docker-commonUpgrade docker-logrotateUpgrade podman-dockerUpgrade docker-rhel-push-pluginUpgrade docker-lvm-pluginUpgrade buildahUpgrade skopeo-debuginfoUpgrade docker-novolume-pluginUpgrade docker-debuginfo | Apr 2, 2020 | Feb 12, 2020 |
| Debian | — | Upgrade golang-github-proglottis-gpgme | Jul 30, 2024 | Feb 12, 2020 |
| Huawei Euleros 2_0_sp8 | — | — | Mar 24, 2020 | Feb 12, 2020 |
| Redhat Openshift | — | Upgrade cri-oUpgrade atomic-openshiftUpgrade skopeoUpgrade machine-config-daemonUpgrade podmanUpgrade openshift-clients | Mar 11, 2020 | Jan 16, 2020 |
| Redhat_linux | — | Upgrade docker-logrotateUpgrade docker-v1.10-migratorUpgrade containers-commonUpgrade docker-clientUpgrade docker-rhel-push-pluginUpgrade podman-dockerUpgrade docker-debuginfoUpgrade docker-novolume-pluginUpgrade skopeo-debuginfoUpgrade docker-lvm-pluginUpgrade docker-commonUpgrade buildahUpgrade podmanUpgrade podman-debuginfoUpgrade dockerUpgrade buildah-debuginfoUpgrade skopeoNo solution exists | Apr 2, 2020 | Feb 12, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub