[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250770

 
 

909

 
 

196157

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2021-20291Date: (C)2021-04-02   (M)2023-12-22


A deadlock vulnerability was found in 'github.com/containers/storage' in versions before 1.28.1. When a container image is processed, each layer is unpacked using `tar`. If one of those layers is not a valid `tar` archive this causes an error leading to an unexpected situation where the code indefinitely waits for the tar unpacked stream, which never finishes. An attacker could use this vulnerability to craft a malicious image, which when downloaded and stored by an application using containers/storage, would then cause a deadlock leading to a Denial of Service (DoS).

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 6.5CVSS Score : 7.1
Exploit Score: 2.8Exploit Score: 8.6
Impact Score: 3.6Impact Score: 6.9
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: NETWORKAccess Vector: NETWORK
Attack Complexity: LOWAccess Complexity: MEDIUM
Privileges Required: NONEAuthentication: NONE
User Interaction: REQUIREDConfidentiality: NONE
Scope: UNCHANGEDIntegrity: NONE
Confidentiality: NONEAvailability: COMPLETE
Integrity: NONE 
Availability: HIGH 
  
Reference:
FEDORA-2021-83b3740389
FEDORA-2021-a3703b9dc8
FEDORA-2021-c56a213327
FEDORA-2021-ec00da7faa
https://bugzilla.redhat.com/show_bug.cgi?id=1939485
https://unit42.paloaltonetworks.com/cve-2021-20291/

CWE    1
CWE-667
OVAL    22
oval:org.secpod.oval:def:506494
oval:org.secpod.oval:def:507396
oval:org.secpod.oval:def:507356
oval:org.secpod.oval:def:507399
...

© SecPod Technologies