Closed nam20485 closed 7 months ago
The following issues were found:
⚠️: The number of snapshots compared for the base SHA (1) and the head SHA (3) do not match. You may see unexpected additions in the diff.
Consider enabling retry-on-snapshot-warnings. See the documentation for more information and troubleshooting advice.
Package | Version | License | Issue Type |
vcpkg/boost-algorithm:x64-osx | 1.82.0 | Null | Unknown License |
vcpkg/boost-align:x64-osx | 1.82.0 | Null | Unknown License |
vcpkg/boost-array:x64-osx | 1.82.0 | Null | Unknown License |
vcpkg/boost-asio:x64-osx | 1.82.0 | Null | Unknown License |
vcpkg/boost-assert:x64-osx | 1.82.0 | Null | Unknown License |
vcpkg/boost-bind:x64-osx | 1.82.0 | Null | Unknown License |
vcpkg/boost-build:x64-osx | 1.82.0 | Null | Unknown License |
vcpkg/boost-chrono:x64-osx | 1.82.0 | Null | Unknown License |
vcpkg/boost-concept-check:x64-osx | 1.82.0 | Null | Unknown License |
vcpkg/boost-config:x64-osx | 1.82.0 | Null | Unknown License |
vcpkg/boost-container-hash:x64-osx | 1.82.0 | Null | Unknown License |
vcpkg/boost-container:x64-osx | 1.82.0 | Null | Unknown License |
vcpkg/boost-context:x64-osx | 1.82.0 | Null | Unknown License |
vcpkg/boost-conversion:x64-osx | 1.82.0 | Null | Unknown License |
vcpkg/boost-core:x64-osx | 1.82.0 | Null | Unknown License |
vcpkg/boost-coroutine:x64-osx | 1.82.0 | Null | Unknown License |
vcpkg/boost-date-time:x64-osx | 1.82.0 | Null | Unknown License |
vcpkg/boost-describe:x64-osx | 1.82.0 | Null | Unknown License |
vcpkg/boost-detail:x64-osx | 1.82.0 | Null | Unknown License |
vcpkg/boost-exception:x64-osx | 1.82.0 | Null | Unknown License |
vcpkg/boost-function-types:x64-osx | 1.82.0 | Null | Unknown License |
vcpkg/boost-function:x64-osx | 1.82.0 | Null | Unknown License |
vcpkg/boost-functional:x64-osx | 1.82.0 | Null | Unknown License |
vcpkg/boost-fusion:x64-osx | 1.82.0 | Null | Unknown License |
vcpkg/boost-integer:x64-osx | 1.82.0 | Null | Unknown License |
vcpkg/boost-intrusive:x64-osx | 1.82.0 | Null | Unknown License |
vcpkg/boost-io:x64-osx | 1.82.0 | Null | Unknown License |
vcpkg/boost-iterator:x64-osx | 1.82.0 | Null | Unknown License |
vcpkg/boost-lexical-cast:x64-osx | 1.82.0 | Null | Unknown License |
vcpkg/boost-modular-build-helper:x64-osx | 1.82.0 | Null | Unknown License |
vcpkg/boost-move:x64-osx | 1.82.0 | Null | Unknown License |
vcpkg/boost-mp11:x64-osx | 1.82.0 | Null | Unknown License |
vcpkg/boost-mpl:x64-osx | 1.82.0 | Null | Unknown License |
vcpkg/boost-numeric-conversion:x64-osx | 1.82.0 | Null | Unknown License |
vcpkg/boost-optional:x64-osx | 1.82.0 | Null | Unknown License |
vcpkg/boost-pool:x64-osx | 1.82.0 | Null | Unknown License |
vcpkg/boost-predef:x64-osx | 1.82.0 | Null | Unknown License |
vcpkg/boost-preprocessor:x64-osx | 1.82.0 | Null | Unknown License |
vcpkg/boost-range:x64-osx | 1.82.0 | Null | Unknown License |
vcpkg/boost-ratio:x64-osx | 1.82.0 | Null | Unknown License |
vcpkg/boost-rational:x64-osx | 1.82.0 | Null | Unknown License |
vcpkg/boost-regex:x64-osx | 1.82.0 | Null | Unknown License |
vcpkg/boost-smart-ptr:x64-osx | 1.82.0 | Null | Unknown License |
vcpkg/boost-static-assert:x64-osx | 1.82.0 | Null | Unknown License |
vcpkg/boost-system:x64-osx | 1.82.0 | Null | Unknown License |
vcpkg/boost-throw-exception:x64-osx | 1.82.0 | Null | Unknown License |
vcpkg/boost-tokenizer:x64-osx | 1.82.0 | Null | Unknown License |
vcpkg/boost-tuple:x64-osx | 1.82.0 | Null | Unknown License |
vcpkg/boost-type-traits:x64-osx | 1.82.0 | Null | Unknown License |
vcpkg/boost-typeof:x64-osx | 1.82.0 | Null | Unknown License |
vcpkg/boost-uninstall:x64-osx | 1.82.0 | Null | Unknown License |
vcpkg/boost-unordered:x64-osx | 1.82.0 | Null | Unknown License |
vcpkg/boost-utility:x64-osx | 1.82.0 | Null | Unknown License |
vcpkg/boost-variant2:x64-osx | 1.82.0 | Null | Unknown License |
vcpkg/boost-vcpkg-helpers:x64-osx | 1.82.0 | Null | Unknown License |
vcpkg/boost-winapi:x64-osx | 1.82.0 | Null | Unknown License |
vcpkg/bzip2:x64-osx | 1.0.8 | Null | Unknown License |
vcpkg/crow:x64-osx | 1.0-5 | Null | Unknown License |
vcpkg/libarchive:x64-osx | 3.6.2 | Null | Unknown License |
vcpkg/libiconv:x64-osx | 1.17 | Null | Unknown License |
vcpkg/liblzma:x64-osx | 5.4.1 | Null | Unknown License |
vcpkg/libxml2:x64-osx | 2.10.3 | Null | Unknown License |
vcpkg/lz4:x64-osx | 1.9.4 | Null | Unknown License |
vcpkg/mbedtls:x64-osx | 2.28.1 | Null | Unknown License |
vcpkg/openssl:x64-osx | 3.1.1 | Null | Unknown License |
vcpkg/protobuf:x64-osx | 3.21.12 | Null | Unknown License |
vcpkg/vcpkg-cmake-config:x64-osx | 2022-02-06 | Null | Unknown License |
vcpkg/vcpkg-cmake-get-vars:x64-osx | 2023-03-02 | Null | Unknown License |
vcpkg/vcpkg-cmake:x64-osx | 2023-05-04 | Null | Unknown License |
vcpkg/zlib:x64-osx | 1.2.13 | Null | Unknown License |
vcpkg/zstd:x64-osx | 1.5.5 | Null | Unknown License |
nam20485/odbdesign:pr-274
nam20485/odbdesign:pr-274
digest | sha256:b683b13350701d1466234ea6b844676769db57a033e8e7d9756806240eae906a |
vulnerabilities | |
platform | linux/amd64 |
size | 40 MB |
packages | 126 |
debian:12-slim
also known as |
|
digest | sha256:6bdbd579ba71f6855deecf57e64524921aed6b97ff1e5195436f244d2cb42b12 |
vulnerabilities |
nam20485/odbdesign:pr-274
debian:12-slim
Name | bookworm-20240211-slim |
Digest | sha256:6bdbd579ba71f6855deecf57e64524921aed6b97ff1e5195436f244d2cb42b12 |
Vulnerabilities | |
Pushed | 2 months ago |
Size | 29 MB |
Packages | 126 |
Flavor | debian |
OS | 12 |
Slim | ✅ |
The base image is also available under the supported tag(s): bookworm-slim
Tag | Details | Pushed | Vulnerabilities |
---|---|---|---|
12-slim Newer image for same tag Also known as:
|
Benefits:
|
1 week ago | |
Tag | Details | Pushed | Vulnerabilities |
---|---|---|---|
stable-slim Tag is preferred tag Also known as: |
Benefits:
|
1 week ago | |
12 Tag is latest Also known as:
|
Benefits:
|
1 week ago | |
12.4-slim Image introduces 1 high vulnerability Also known as:
|
Benefits:
|
2 months ago | |
12.4 Image introduces 1 high vulnerability Also known as:
|
Benefits:
|
2 months ago | |
Image reference | ghcr.io/nam20485/odbdesign:development-latest |
nam20485/odbdesign:pr-274 |
---|---|---|
- digest | 4edccf4fbeea |
00a3224f0651 |
- provenance | https://github.com/nam20485/OdbDesign/commit/ebf05b0ea5f05287e6d8f09a83aa0f901386de9f | https://github.com/nam20485/OdbDesign/commit/c35fd6fffa42a8ec5c132ec1316d572b999acebb |
- vulnerabilities | ||
- platform | linux/amd64 | linux/amd64 |
- size | 36 MB | 40 MB (+4.3 MB) |
- packages | 126 | 126 |
Base Image | debian:12-slim also known as: • bookworm-slim |
debian:12-slim also known as: • bookworm-slim |
- vulnerabilities |
nam20485/odbdesign:pr-274
nam20485/odbdesign:pr-274
digest | sha256:2e69633e60ab61a7c3cb087bf4d76dd90117f61cd939ada1b99001738f250f8e |
vulnerabilities | |
platform | linux/amd64 |
size | 40 MB |
packages | 126 |
debian:12-slim
also known as |
|
digest | sha256:6bdbd579ba71f6855deecf57e64524921aed6b97ff1e5195436f244d2cb42b12 |
vulnerabilities |
libgcrypt20
|
Affected range | >=1.10.1-3 |
Fixed version | Not Fixed |
A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-style attack, which can lead to the decryption of RSA ciphertexts.
Affected range | >=1.10.1-3 |
Fixed version | Not Fixed |
cipher/elgamal.c in Libgcrypt through 1.8.2, when used to encrypt messages directly, improperly encodes plaintexts, which allows attackers to obtain sensitive information by reading ciphertext data (i.e., it does not have semantic security in face of a ciphertext-only attack). The Decisional Diffie-Hellman (DDH) assumption does not hold for Libgcrypt's ElGamal implementation.
2.36-9+deb12u4
(deb)pkg:deb/debian/glibc@2.36-9+deb12u4?os_distro=bookworm&os_name=debian&os_version=12
Affected range | >=2.36-9+deb12u4 |
Fixed version | Not Fixed |
In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\1\\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability because the behavior occurs only with a crafted pattern
Affected range | >=2.36-9+deb12u4 |
Fixed version | Not Fixed |
GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is: glibc. NOTE: the vendor's position is "ASLR bypass itself is not a vulnerability.
Affected range | >=2.36-9+deb12u4 |
Fixed version | Not Fixed |
GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments indicate "this is being treated as a non-security bug and no real threat.
Affected range | >=2.36-9+deb12u4 |
Fixed version | Not Fixed |
GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate "this is being treated as a non-security bug and no real threat.
Affected range | >=2.36-9+deb12u4 |
Fixed version | Not Fixed |
GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments indicate "this is being treated as a non-security bug and no real threat.
Affected range | >=2.36-9+deb12u4 |
Fixed version | Not Fixed |
In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\227|)(\\1\\1|t1|\\\2537)+' in grep.
Affected range | >=2.36-9+deb12u4 |
Fixed version | Not Fixed |
The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632.
Affected range | >=2.36-9+deb12u4 |
Fixed version | Not Fixed |
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT character set, which may be used to crash an application or overwrite a neighbouring variable.
252.22-1~deb12u1
(deb)pkg:deb/debian/systemd@252.22-1~deb12u1?os_distro=bookworm&os_name=debian&os_version=12
Affected range | >=252.22-1~deb12u1 |
Fixed version | Not Fixed |
An issue was discovered in systemd 253. An attacker can modify the contents of past events in a sealed log file and then adjust the file such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent "a reply denying that any of the finding was a security vulnerability."
Affected range | >=252.22-1~deb12u1 |
Fixed version | Not Fixed |
An issue was discovered in systemd 253. An attacker can truncate a sealed log file and then resume log sealing such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent "a reply denying that any of the finding was a security vulnerability."
Affected range | >=252.22-1~deb12u1 |
Fixed version | Not Fixed |
An issue was discovered in systemd 253. An attacker can modify a sealed log file such that, in some views, not all existing and sealed log messages are displayed. NOTE: the vendor reportedly sent "a reply denying that any of the finding was a security vulnerability."
Affected range | >=252.22-1~deb12u1 |
Fixed version | Not Fixed |
systemd, when updating file permissions, allows local users to change the permissions and SELinux security contexts for arbitrary files via a symlink attack on unspecified files.
5.36.0-7+deb12u1
(deb)pkg:deb/debian/perl@5.36.0-7+deb12u1?os_distro=bookworm&os_name=debian&os_version=12
Affected range | >=5.36.0-7+deb12u1 |
Fixed version | Not Fixed |
HTTP::Tiny before 0.083, a Perl core module since 5.13.9 and available standalone on CPAN, has an insecure default TLS configuration where users must opt in to verify certificates.
Affected range | >=5.36.0-7+deb12u1 |
Fixed version | Not Fixed |
_is_safe in the File::Temp module for Perl does not properly handle symlinks.
1:4.13+dfsg1-1
(deb)pkg:deb/debian/shadow@1:4.13+dfsg1-1?os_distro=bookworm&os_name=debian&os_version=12
Affected range | >=1:4.13+dfsg1-1 |
Fixed version | Not Fixed |
shadow 4.8, in certain circumstances affecting at least Gentoo, Arch Linux, and Void Linux, allows local users to obtain root access because setuid programs are misconfigured. Specifically, this affects shadow 4.8 when compiled using --with-libpam but without explicitly passing --disable-account-tools-setuid, and without a PAM configuration suitable for use with setuid account management tools. This combination leads to account management tools (groupadd, groupdel, groupmod, useradd, userdel, usermod) that can easily be used by unprivileged local users to escalate privileges to root in multiple ways. This issue became much more relevant in approximately December 2019 when an unrelated bug was fixed (i.e., the chmod calls to suidusbins were fixed in the upstream Makefile which is now included in the release version 4.8).
Affected range | >=1:4.13+dfsg1-1 |
Fixed version | Not Fixed |
initscripts in rPath Linux 1 sets insecure permissions for the /var/log/btmp file, which allows local users to obtain sensitive information regarding authentication attempts. NOTE: because sshd detects the insecure permissions and does not log certain events, this also prevents sshd from logging failed authentication attempts by remote attackers.
2.38.1-5
(deb)pkg:deb/debian/util-linux@2.38.1-5?os_distro=bookworm&os_name=debian&os_version=12
Affected range | >=2.38.1-5 |
Fixed version | Not Fixed |
A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an "INPUTRC" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4.
Affected range | <2.38.1-5+deb12u1 |
Fixed version | 2.38.1-5+deb12u1 |
wall in util-linux through 2.40, often installed with setgid tty permissions, allows escape sequences to be sent to other users' terminals through argv. (Specifically, escape sequences received from stdin are blocked, but escape sequences received from argv are not blocked.) There may be plausible scenarios where this leads to account takeover.
2.38.1-5+b1
(deb)pkg:deb/debian/util-linux@2.38.1-5+b1?os_distro=bookworm&os_name=debian&os_version=12
Affected range | >=2.38.1-5 |
Fixed version | Not Fixed |
A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an "INPUTRC" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4.
Affected range | <2.38.1-5+deb12u1 |
Fixed version | 2.38.1-5+deb12u1 |
wall in util-linux through 2.40, often installed with setgid tty permissions, allows escape sequences to be sent to other users' terminals through argv. (Specifically, escape sequences received from stdin are blocked, but escape sequences received from argv are not blocked.) There may be plausible scenarios where this leads to account takeover.
9.1-1
(deb)pkg:deb/debian/coreutils@9.1-1?os_distro=bookworm&os_name=debian&os_version=12
Affected range | >=9.1-1 |
Fixed version | Not Fixed |
In GNU Coreutils through 8.29, chown-core.c in chown and chgrp does not prevent replacement of a plain file with a symlink during use of the POSIX "-R -L" options, which allows local users to modify the ownership of arbitrary files by leveraging a race condition.
2.6.1
(deb)pkg:deb/debian/apt@2.6.1?os_distro=bookworm&os_name=debian&os_version=12
Affected range | >=2.6.1 |
Fixed version | Not Fixed |
It was found that apt-key in apt, all versions, do not correctly validate gpg keys with the master keyring, leading to a potential man-in-the-middle attack.
3.7.9-2+deb12u2
(deb)pkg:deb/debian/gnutls28@3.7.9-2+deb12u2?os_distro=bookworm&os_name=debian&os_version=12
Affected range | >=3.7.9-2+deb12u2 |
Fixed version | Not Fixed |
The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which allows man-in-the-middle attackers to obtain plaintext HTTP headers via a blockwise chosen-boundary attack (BCBA) on an HTTPS session, in conjunction with JavaScript code that uses (1) the HTML5 WebSocket API, (2) the Java URLConnection API, or (3) the Silverlight WebClient API, aka a "BEAST" attack.
2.2.40-1.1
(deb)pkg:deb/debian/gnupg2@2.2.40-1.1?os_distro=bookworm&os_name=debian&os_version=12
Affected range | >=2.2.40-1.1 |
Fixed version | Not Fixed |
GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB.
1.34+dfsg-1.2+deb12u1
(deb)pkg:deb/debian/tar@1.34+dfsg-1.2+deb12u1?os_distro=bookworm&os_name=debian&os_version=12
Affected range | >=1.34+dfsg-1.2+deb12u1 |
Fixed version | Not Fixed |
Tar 1.15.1 does not properly warn the user when extracting setuid or setgid files, which may allow local users or remote attackers to gain privileges.
nam20485/odbdesign:pr-274
debian:12-slim
Name | bookworm-20240211-slim |
Digest | sha256:6bdbd579ba71f6855deecf57e64524921aed6b97ff1e5195436f244d2cb42b12 |
Vulnerabilities | |
Pushed | 2 months ago |
Size | 29 MB |
Packages | 126 |
Flavor | debian |
OS | 12 |
Slim | ✅ |
The base image is also available under the supported tag(s): bookworm-slim
Tag | Details | Pushed | Vulnerabilities |
---|---|---|---|
12-slim Newer image for same tag Also known as:
|
Benefits:
|
1 week ago | |
Tag | Details | Pushed | Vulnerabilities |
---|---|---|---|
stable-slim Tag is preferred tag Also known as: |
Benefits:
|
1 week ago | |
12 Tag is latest Also known as:
|
Benefits:
|
1 week ago | |
12.4-slim Image introduces 1 high vulnerability Also known as:
|
Benefits:
|
2 months ago | |
12.4 Image introduces 1 high vulnerability Also known as:
|
Benefits:
|
2 months ago | |
nam20485/odbdesign:pr-274
nam20485/odbdesign:pr-274
digest | sha256:00a3224f0651fe5be6d377bcd3a5871f683fb63200d2572bc19a5eb4bc77f5f3 |
vulnerabilities | |
platform | linux/amd64 |
size | 40 MB |
packages | 126 |
debian:12-slim
also known as |
|
digest | sha256:6bdbd579ba71f6855deecf57e64524921aed6b97ff1e5195436f244d2cb42b12 |
vulnerabilities |
libgcrypt20
|
Affected range | >=1.10.1-3 |
Fixed version | Not Fixed |
A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-style attack, which can lead to the decryption of RSA ciphertexts.
Affected range | >=1.10.1-3 |
Fixed version | Not Fixed |
cipher/elgamal.c in Libgcrypt through 1.8.2, when used to encrypt messages directly, improperly encodes plaintexts, which allows attackers to obtain sensitive information by reading ciphertext data (i.e., it does not have semantic security in face of a ciphertext-only attack). The Decisional Diffie-Hellman (DDH) assumption does not hold for Libgcrypt's ElGamal implementation.
2.36-9+deb12u4
(deb)pkg:deb/debian/glibc@2.36-9+deb12u4?os_distro=bookworm&os_name=debian&os_version=12
Affected range | >=2.36-9+deb12u4 |
Fixed version | Not Fixed |
In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\1\\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability because the behavior occurs only with a crafted pattern
Affected range | >=2.36-9+deb12u4 |
Fixed version | Not Fixed |
GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is: glibc. NOTE: the vendor's position is "ASLR bypass itself is not a vulnerability.
Affected range | >=2.36-9+deb12u4 |
Fixed version | Not Fixed |
GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments indicate "this is being treated as a non-security bug and no real threat.
Affected range | >=2.36-9+deb12u4 |
Fixed version | Not Fixed |
GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate "this is being treated as a non-security bug and no real threat.
Affected range | >=2.36-9+deb12u4 |
Fixed version | Not Fixed |
GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments indicate "this is being treated as a non-security bug and no real threat.
Affected range | >=2.36-9+deb12u4 |
Fixed version | Not Fixed |
In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\227|)(\\1\\1|t1|\\\2537)+' in grep.
Affected range | >=2.36-9+deb12u4 |
Fixed version | Not Fixed |
The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632.
Affected range | >=2.36-9+deb12u4 |
Fixed version | Not Fixed |
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT character set, which may be used to crash an application or overwrite a neighbouring variable.
252.22-1~deb12u1
(deb)pkg:deb/debian/systemd@252.22-1~deb12u1?os_distro=bookworm&os_name=debian&os_version=12
Affected range | >=252.22-1~deb12u1 |
Fixed version | Not Fixed |
An issue was discovered in systemd 253. An attacker can modify the contents of past events in a sealed log file and then adjust the file such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent "a reply denying that any of the finding was a security vulnerability."
Affected range | >=252.22-1~deb12u1 |
Fixed version | Not Fixed |
An issue was discovered in systemd 253. An attacker can truncate a sealed log file and then resume log sealing such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent "a reply denying that any of the finding was a security vulnerability."
Affected range | >=252.22-1~deb12u1 |
Fixed version | Not Fixed |
An issue was discovered in systemd 253. An attacker can modify a sealed log file such that, in some views, not all existing and sealed log messages are displayed. NOTE: the vendor reportedly sent "a reply denying that any of the finding was a security vulnerability."
Affected range | >=252.22-1~deb12u1 |
Fixed version | Not Fixed |
systemd, when updating file permissions, allows local users to change the permissions and SELinux security contexts for arbitrary files via a symlink attack on unspecified files.
5.36.0-7+deb12u1
(deb)pkg:deb/debian/perl@5.36.0-7+deb12u1?os_distro=bookworm&os_name=debian&os_version=12
Affected range | >=5.36.0-7+deb12u1 |
Fixed version | Not Fixed |
HTTP::Tiny before 0.083, a Perl core module since 5.13.9 and available standalone on CPAN, has an insecure default TLS configuration where users must opt in to verify certificates.
Affected range | >=5.36.0-7+deb12u1 |
Fixed version | Not Fixed |
_is_safe in the File::Temp module for Perl does not properly handle symlinks.
1:4.13+dfsg1-1
(deb)pkg:deb/debian/shadow@1:4.13+dfsg1-1?os_distro=bookworm&os_name=debian&os_version=12
Affected range | >=1:4.13+dfsg1-1 |
Fixed version | Not Fixed |
shadow 4.8, in certain circumstances affecting at least Gentoo, Arch Linux, and Void Linux, allows local users to obtain root access because setuid programs are misconfigured. Specifically, this affects shadow 4.8 when compiled using --with-libpam but without explicitly passing --disable-account-tools-setuid, and without a PAM configuration suitable for use with setuid account management tools. This combination leads to account management tools (groupadd, groupdel, groupmod, useradd, userdel, usermod) that can easily be used by unprivileged local users to escalate privileges to root in multiple ways. This issue became much more relevant in approximately December 2019 when an unrelated bug was fixed (i.e., the chmod calls to suidusbins were fixed in the upstream Makefile which is now included in the release version 4.8).
Affected range | >=1:4.13+dfsg1-1 |
Fixed version | Not Fixed |
initscripts in rPath Linux 1 sets insecure permissions for the /var/log/btmp file, which allows local users to obtain sensitive information regarding authentication attempts. NOTE: because sshd detects the insecure permissions and does not log certain events, this also prevents sshd from logging failed authentication attempts by remote attackers.
2.38.1-5
(deb)pkg:deb/debian/util-linux@2.38.1-5?os_distro=bookworm&os_name=debian&os_version=12
Affected range | >=2.38.1-5 |
Fixed version | Not Fixed |
A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an "INPUTRC" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4.
Affected range | <2.38.1-5+deb12u1 |
Fixed version | 2.38.1-5+deb12u1 |
wall in util-linux through 2.40, often installed with setgid tty permissions, allows escape sequences to be sent to other users' terminals through argv. (Specifically, escape sequences received from stdin are blocked, but escape sequences received from argv are not blocked.) There may be plausible scenarios where this leads to account takeover.
2.38.1-5+b1
(deb)pkg:deb/debian/util-linux@2.38.1-5+b1?os_distro=bookworm&os_name=debian&os_version=12
Affected range | >=2.38.1-5 |
Fixed version | Not Fixed |
A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an "INPUTRC" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4.
Affected range | <2.38.1-5+deb12u1 |
Fixed version | 2.38.1-5+deb12u1 |
wall in util-linux through 2.40, often installed with setgid tty permissions, allows escape sequences to be sent to other users' terminals through argv. (Specifically, escape sequences received from stdin are blocked, but escape sequences received from argv are not blocked.) There may be plausible scenarios where this leads to account takeover.
3.7.9-2+deb12u2
(deb)pkg:deb/debian/gnutls28@3.7.9-2+deb12u2?os_distro=bookworm&os_name=debian&os_version=12
Affected range | >=3.7.9-2+deb12u2 |
Fixed version | Not Fixed |
The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which allows man-in-the-middle attackers to obtain plaintext HTTP headers via a blockwise chosen-boundary attack (BCBA) on an HTTPS session, in conjunction with JavaScript code that uses (1) the HTML5 WebSocket API, (2) the Java URLConnection API, or (3) the Silverlight WebClient API, aka a "BEAST" attack.
2.6.1
(deb)pkg:deb/debian/apt@2.6.1?os_distro=bookworm&os_name=debian&os_version=12
Affected range | >=2.6.1 |
Fixed version | Not Fixed |
It was found that apt-key in apt, all versions, do not correctly validate gpg keys with the master keyring, leading to a potential man-in-the-middle attack.
2.2.40-1.1
(deb)pkg:deb/debian/gnupg2@2.2.40-1.1?os_distro=bookworm&os_name=debian&os_version=12
Affected range | >=2.2.40-1.1 |
Fixed version | Not Fixed |
GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB.
1.34+dfsg-1.2+deb12u1
(deb)pkg:deb/debian/tar@1.34+dfsg-1.2+deb12u1?os_distro=bookworm&os_name=debian&os_version=12
Affected range | >=1.34+dfsg-1.2+deb12u1 |
Fixed version | Not Fixed |
Tar 1.15.1 does not properly warn the user when extracting setuid or setgid files, which may allow local users or remote attackers to gain privileges.
9.1-1
(deb)pkg:deb/debian/coreutils@9.1-1?os_distro=bookworm&os_name=debian&os_version=12
Affected range | >=9.1-1 |
Fixed version | Not Fixed |
In GNU Coreutils through 8.29, chown-core.c in chown and chgrp does not prevent replacement of a plain file with a symlink during use of the POSIX "-R -L" options, which allows local users to modify the ownership of arbitrary files by leveraging a race condition.
nam20485/odbdesign:pr-274
Base image is debian:12-slim
Name | bookworm-20240211-slim |
Digest | sha256:6bdbd579ba71f6855deecf57e64524921aed6b97ff1e5195436f244d2cb42b12 |
Vulnerabilities | |
Pushed | 2 months ago |
Size | 29 MB |
Packages | 126 |
Flavor | debian |
OS | 12 |
Slim | ✅ |
The base image is also available under the supported tag(s): bookworm-slim
Rebuild the image using a newer base image version. Updating this may result in breaking changes.
Tag | Details | Pushed | Vulnerabilities |
---|---|---|---|
12-slim Newer image for same tag Also known as:
|
Benefits:
|
1 week ago | |
Tag | Details | Pushed | Vulnerabilities |
---|---|---|---|
stable-slim Tag is preferred tag Also known as: |
Benefits:
|
1 week ago | |
12 Tag is latest Also known as:
|
Benefits:
|
1 week ago | |
12.4-slim Image introduces 1 high vulnerability Also known as:
|
Benefits:
|
2 months ago | |
12.4 Image introduces 1 high vulnerability Also known as:
|
Benefits:
|
2 months ago | |
fixes #39