Vulnerabilities

1 via 1 paths

Dependencies

15

Source

Group 6 Copy Created with Sketch. Docker

Target OS

alpine:3.2.3
Test your Docker Hub image against our market leading vulnerability database Sign up for free
Severity
  • 1
Status
  • 1
  • 0
  • 0

high severity

Resource Management Errors

  • Vulnerable module: busybox/busybox
  • Introduced through: busybox/busybox@1.23.2-r3
  • Fixed in: 1.24.2-r1

Detailed paths

  • Introduced through: alpine@3.2 busybox/busybox@1.23.2-r3

NVD Description

Note: Versions mentioned in the description apply only to the upstream busybox package and not the busybox package as distributed by Alpine. See How to fix? for Alpine:3.2 relevant fixed versions and status.

The recv_and_process_client_pkt function in networking/ntpd.c in busybox allows remote attackers to cause a denial of service (CPU and bandwidth consumption) via a forged NTP packet, which triggers a communication loop.

Remediation

Upgrade Alpine:3.2 busybox to version 1.24.2-r1 or higher.

References