Vulnerabilities

4 via 10 paths

Dependencies

15

Source

Group 6 Copy Created with Sketch. Docker

Target OS

alpine:3.19.9
Test your Docker Hub image against our market leading vulnerability database Sign up for free
Severity
  • 4
Status
  • 4
  • 0
  • 0

low severity

CVE-2025-46394

  • Vulnerable module: busybox/busybox
  • Introduced through: busybox/busybox@1.36.1-r20, busybox/busybox-binsh@1.36.1-r20 and others
  • Fixed in: 1.36.1-r21

Detailed paths

  • Introduced through: alpine@3.19 busybox/busybox@1.36.1-r20
  • Introduced through: alpine@3.19 busybox/busybox-binsh@1.36.1-r20
  • Introduced through: alpine@3.19 busybox/ssl_client@1.36.1-r20

NVD Description

Note: Versions mentioned in the description apply only to the upstream busybox package and not the busybox package as distributed by Alpine. See How to fix? for Alpine:3.19 relevant fixed versions and status.

In tar in BusyBox through 1.37.0, a TAR archive can have filenames hidden from a listing through the use of terminal escape sequences.

Remediation

Upgrade Alpine:3.19 busybox to version 1.36.1-r21 or higher.

References

low severity

Improper Resource Shutdown or Release

  • Vulnerable module: musl/musl
  • Introduced through: musl/musl@1.2.4_git20230717-r5 and musl/musl-utils@1.2.4_git20230717-r5
  • Fixed in: 1.2.4_git20230717-r6

Detailed paths

  • Introduced through: alpine@3.19 musl/musl@1.2.4_git20230717-r5
  • Introduced through: alpine@3.19 musl/musl-utils@1.2.4_git20230717-r5

NVD Description

Note: Versions mentioned in the description apply only to the upstream musl package and not the musl package as distributed by Alpine. See How to fix? for Alpine:3.19 relevant fixed versions and status.

A security flaw has been discovered in musl libc up to 1.2.6. Affected is the function iconv of the file src/locale/iconv.c of the component GB18030 4-byte Decoder. Performing a manipulation results in inefficient algorithmic complexity. The attack must be initiated from a local position. To fix this issue, it is recommended to deploy a patch.

Remediation

Upgrade Alpine:3.19 musl to version 1.2.4_git20230717-r6 or higher.

References

low severity

CVE-2024-58251

  • Vulnerable module: busybox/busybox
  • Introduced through: busybox/busybox@1.36.1-r20, busybox/busybox-binsh@1.36.1-r20 and others
  • Fixed in: 1.36.1-r21

Detailed paths

  • Introduced through: alpine@3.19 busybox/busybox@1.36.1-r20
  • Introduced through: alpine@3.19 busybox/busybox-binsh@1.36.1-r20
  • Introduced through: alpine@3.19 busybox/ssl_client@1.36.1-r20

NVD Description

Note: Versions mentioned in the description apply only to the upstream busybox package and not the busybox package as distributed by Alpine. See How to fix? for Alpine:3.19 relevant fixed versions and status.

In netstat in BusyBox through 1.37.0, local users can launch of network application with an argv[0] containing an ANSI terminal escape sequence, leading to a denial of service (terminal locked up) when netstat is used by a victim.

Remediation

Upgrade Alpine:3.19 busybox to version 1.36.1-r21 or higher.

References

low severity

Always-Incorrect Control Flow Implementation

  • Vulnerable module: musl/musl
  • Introduced through: musl/musl@1.2.4_git20230717-r5 and musl/musl-utils@1.2.4_git20230717-r5
  • Fixed in: 1.2.4_git20230717-r6

Detailed paths

  • Introduced through: alpine@3.19 musl/musl@1.2.4_git20230717-r5
  • Introduced through: alpine@3.19 musl/musl-utils@1.2.4_git20230717-r5

NVD Description

Note: Versions mentioned in the description apply only to the upstream musl package and not the musl package as distributed by Alpine. See How to fix? for Alpine:3.19 relevant fixed versions and status.

An issue was discovered in musl libc 0.7.10 through 1.2.6. Stack-based memory corruption can occur during qsort of very large arrays, due to incorrectly implemented double-word primitives. The number of elements must exceed about seven million, i.e., the 32nd Leonardo number on 32-bit platforms (or the 64th Leonardo number on 64-bit platforms, which is not practical).

Remediation

Upgrade Alpine:3.19 musl to version 1.2.4_git20230717-r6 or higher.

References