[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249966

 
 

909

 
 

195636

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2DOCKER-2021-014 --- containerd

ID: oval:org.secpod.oval:def:1700745Date: (C)2021-12-10   (M)2023-11-24
Class: PATCHFamily: unix




In the OCI Distribution Specification version 1.0.0 and prior and in the OCI Image Specification version 1.0.1 and prior, manifest and index documents are ambiguous without an accompanying Content-Type HTTP header. Versions of Moby prior to 20.10.11 and versions of containerd prior to 1.4.12 and 1.5.8 treat the Content-Type header as trusted and deserialize the document according to that header. If the Content-Type header changed between pulls of the same ambiguous document , the document may be interpreted differently, meaning that the digest alone is insufficient to unambiguously identify the content of the image

Platform:
Amazon Linux 2
Product:
containerd
docker
Reference:
ALAS2DOCKER-2021-014
CVE-2021-41190
CVE    1
CVE-2021-41190
CPE    3
cpe:/o:amazon:linux:2
cpe:/a:docker:docker
cpe:/a:containerd.io:containerd

© SecPod Technologies