Vulnerabilities |
4 via 10 paths |
|---|---|
Dependencies |
15 |
Source |
Docker |
Target OS |
alpine:3.19.9 |
low severity
- Vulnerable module: busybox/busybox
- Introduced through: busybox/busybox@1.36.1-r20, busybox/busybox-binsh@1.36.1-r20 and others
- Fixed in: 1.36.1-r21
Detailed paths
-
Introduced through: alpine@3.19 › busybox/busybox@1.36.1-r20
-
Introduced through: alpine@3.19 › busybox/busybox-binsh@1.36.1-r20
-
Introduced through: alpine@3.19 › busybox/ssl_client@1.36.1-r20
NVD Description
Note: Versions mentioned in the description apply only to the upstream busybox package and not the busybox package as distributed by Alpine.
See How to fix? for Alpine:3.19 relevant fixed versions and status.
In tar in BusyBox through 1.37.0, a TAR archive can have filenames hidden from a listing through the use of terminal escape sequences.
Remediation
Upgrade Alpine:3.19 busybox to version 1.36.1-r21 or higher.
References
low severity
- Vulnerable module: musl/musl
- Introduced through: musl/musl@1.2.4_git20230717-r5 and musl/musl-utils@1.2.4_git20230717-r5
- Fixed in: 1.2.4_git20230717-r6
Detailed paths
-
Introduced through: alpine@3.19 › musl/musl@1.2.4_git20230717-r5
-
Introduced through: alpine@3.19 › musl/musl-utils@1.2.4_git20230717-r5
NVD Description
Note: Versions mentioned in the description apply only to the upstream musl package and not the musl package as distributed by Alpine.
See How to fix? for Alpine:3.19 relevant fixed versions and status.
A security flaw has been discovered in musl libc up to 1.2.6. Affected is the function iconv of the file src/locale/iconv.c of the component GB18030 4-byte Decoder. Performing a manipulation results in inefficient algorithmic complexity. The attack must be initiated from a local position. To fix this issue, it is recommended to deploy a patch.
Remediation
Upgrade Alpine:3.19 musl to version 1.2.4_git20230717-r6 or higher.
References
low severity
- Vulnerable module: busybox/busybox
- Introduced through: busybox/busybox@1.36.1-r20, busybox/busybox-binsh@1.36.1-r20 and others
- Fixed in: 1.36.1-r21
Detailed paths
-
Introduced through: alpine@3.19 › busybox/busybox@1.36.1-r20
-
Introduced through: alpine@3.19 › busybox/busybox-binsh@1.36.1-r20
-
Introduced through: alpine@3.19 › busybox/ssl_client@1.36.1-r20
NVD Description
Note: Versions mentioned in the description apply only to the upstream busybox package and not the busybox package as distributed by Alpine.
See How to fix? for Alpine:3.19 relevant fixed versions and status.
In netstat in BusyBox through 1.37.0, local users can launch of network application with an argv[0] containing an ANSI terminal escape sequence, leading to a denial of service (terminal locked up) when netstat is used by a victim.
Remediation
Upgrade Alpine:3.19 busybox to version 1.36.1-r21 or higher.
References
low severity
- Vulnerable module: musl/musl
- Introduced through: musl/musl@1.2.4_git20230717-r5 and musl/musl-utils@1.2.4_git20230717-r5
- Fixed in: 1.2.4_git20230717-r6
Detailed paths
-
Introduced through: alpine@3.19 › musl/musl@1.2.4_git20230717-r5
-
Introduced through: alpine@3.19 › musl/musl-utils@1.2.4_git20230717-r5
NVD Description
Note: Versions mentioned in the description apply only to the upstream musl package and not the musl package as distributed by Alpine.
See How to fix? for Alpine:3.19 relevant fixed versions and status.
An issue was discovered in musl libc 0.7.10 through 1.2.6. Stack-based memory corruption can occur during qsort of very large arrays, due to incorrectly implemented double-word primitives. The number of elements must exceed about seven million, i.e., the 32nd Leonardo number on 32-bit platforms (or the 64th Leonardo number on 64-bit platforms, which is not practical).
Remediation
Upgrade Alpine:3.19 musl to version 1.2.4_git20230717-r6 or higher.