7.5
CVE-2020-8945
- EPSS 5.07%
- Veröffentlicht 12.02.2020 18:15:10
- Zuletzt bearbeitet 21.11.2024 05:39:42
- Erkennungen
The proglottis Go wrapper before 0.1.1 for the GPGME library has a use-after-free, as demonstrated by use for container image pulls by Docker or CRI-O. This leads to a crash or potential code execution during GPG signature verification.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Gpgme Project ≫ Gpgme SwPlatform go Version < 0.1.1
Redhat ≫ Openshift Container Platform Version 3.11
Redhat ≫ Openshift Container Platform Version 4.1
Redhat ≫ Openshift Container Platform Version 4.2
Redhat ≫ Openshift Container Platform Version 4.3
Redhat ≫ Openshift Container Platform Version 4.4
Redhat ≫ Openshift Container Platform Version 4.5
Redhat ≫ Openshift Container Platform For Ibm Z Version 4.1
Redhat ≫ Openshift Container Platform For Ibm Z Version 4.2
Redhat ≫ Openshift Container Platform For Linuxone Version 4.1
Redhat ≫ Openshift Container Platform For Linuxone Version 4.2
Fedoraproject ≫ Fedora Version 30
Fedoraproject ≫ Fedora Version 31
Fedoraproject ≫ Fedora Version 32
Redhat ≫ Enterprise Linux For Ibm Z Systems Version 7.0
Redhat ≫ Enterprise Linux For Power Little Endian Version 7.0
Redhat ≫ Enterprise Linux Server Version 7.0
Redhat ≫ Enterprise Linux Workstation Version 7.0
Redhat ≫ Openshift Container Platform Version 3.11
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 5.07% | 0.912 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 1.6 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
|
| NIST | 5.1 | 4.9 | 6.4 |
AV:N/AC:H/Au:N/C:P/I:P/A:P
|
CWE-416 Use After Free
The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.
https://access.redhat.com/errata/RHSA-2020:0679
https://access.redhat.com/errata/RHSA-2020:0689
https://access.redhat.com/errata/RHSA-2020:0697
https://bugzilla.redhat.com/show_bug.cgi?id=1795838
https://github.com/containers/image/commit/4c7a23f82ef09127b0ff28366d1cf31316dd6cc1
https://github.com/proglottis/gpgme/compare/v0.1.0...v0.1.1
https://github.com/proglottis/gpgme/pull/23
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3SOCLOPTSYABTE4CLTSPDIFE6ZZZR4LX/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H6P6SSNKN4H6GSEVROHBDXA64PX7EOED/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KDBT77KV3U7BESJX3P4S4MPVDGRTAQA2/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WXV7NZELYWRRCXATXU3FYD3G3WJT3WYM/