Description
The proglottis Go wrapper before 0.1.1 for the GPGME library has a use-after-free, as demonstrated by use for container image pulls by Docker or CRI-O. This leads to a crash or potential code execution during GPG signature verification.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-1136 | The proglottis Go wrapper before 0.1.1 for the GPGME library has a use-after-free, as demonstrated by use for container image pulls by Docker or CRI-O. This leads to a crash or potential code execution during GPG signature verification. |
Github GHSA |
GHSA-m6wg-2mwg-4rfq | GPGME Go wrapper contains Use After Free |
References
History
No history.
Subscriptions
Fedoraproject
Subscribe
Fedora
Subscribe
Gpgme Project
Subscribe
Gpgme
Subscribe
Redhat
Subscribe
Enterprise Linux
Subscribe
Enterprise Linux For Ibm Z Systems
Subscribe
Enterprise Linux For Power Little Endian
Subscribe
Enterprise Linux Server
Subscribe
Enterprise Linux Workstation
Subscribe
Openshift
Subscribe
Openshift Container Platform
Subscribe
Openshift Container Platform For Ibm Z
Subscribe
Openshift Container Platform For Linuxone
Subscribe
Rhel Extras Other
Subscribe
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T10:12:10.975Z
Reserved: 2020-02-12T00:00:00.000Z
Link: CVE-2020-8945
No data.
Status : Modified
Published: 2020-02-12T18:15:10.470
Modified: 2024-11-21T05:39:42.933
Link: CVE-2020-8945
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA