[ALPINE:CVE-2024-28180] buildah vulnerability

Severity Medium
Affected Packages 8
Fixed Packages 8
CVEs 1

[From CVE-2024-28180] Package jose aims to provide an implementation of the Javascript Object Signing and Encryption set of standards. An attacker could send a JWE containing compressed data that used large amounts of memory and CPU when decompressed by Decrypt or DecryptMulti. Those functions now return an error if the decompressed data would exceed 250kB or 10x the compressed size (whichever is larger). This vulnerability has been patched in versions 4.0.1, 3.0.3 and 2.6.3.

Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Fixed pkg:apk/alpine/buildah?arch=x86_64&distro=alpine-edge alpine buildah = 1.35.4-r0 alpine-edge x86_64
Affected pkg:apk/alpine/buildah?arch=x86_64&distro=alpine-edge alpine buildah < 1.35.4-r0 alpine-edge x86_64
Fixed pkg:apk/alpine/buildah?arch=x86&distro=alpine-edge alpine buildah = 1.35.4-r0 alpine-edge x86
Affected pkg:apk/alpine/buildah?arch=x86&distro=alpine-edge alpine buildah < 1.35.4-r0 alpine-edge x86
Fixed pkg:apk/alpine/buildah?arch=s390x&distro=alpine-edge alpine buildah = 1.35.4-r0 alpine-edge s390x
Affected pkg:apk/alpine/buildah?arch=s390x&distro=alpine-edge alpine buildah < 1.35.4-r0 alpine-edge s390x
Fixed pkg:apk/alpine/buildah?arch=riscv64&distro=alpine-edge alpine buildah = 1.35.4-r0 alpine-edge riscv64
Affected pkg:apk/alpine/buildah?arch=riscv64&distro=alpine-edge alpine buildah < 1.35.4-r0 alpine-edge riscv64
Fixed pkg:apk/alpine/buildah?arch=ppc64le&distro=alpine-edge alpine buildah = 1.35.4-r0 alpine-edge ppc64le
Affected pkg:apk/alpine/buildah?arch=ppc64le&distro=alpine-edge alpine buildah < 1.35.4-r0 alpine-edge ppc64le
Fixed pkg:apk/alpine/buildah?arch=armv7&distro=alpine-edge alpine buildah = 1.35.4-r0 alpine-edge armv7
Affected pkg:apk/alpine/buildah?arch=armv7&distro=alpine-edge alpine buildah < 1.35.4-r0 alpine-edge armv7
Fixed pkg:apk/alpine/buildah?arch=armhf&distro=alpine-edge alpine buildah = 1.35.4-r0 alpine-edge armhf
Affected pkg:apk/alpine/buildah?arch=armhf&distro=alpine-edge alpine buildah < 1.35.4-r0 alpine-edge armhf
Fixed pkg:apk/alpine/buildah?arch=aarch64&distro=alpine-edge alpine buildah = 1.35.4-r0 alpine-edge aarch64
Affected pkg:apk/alpine/buildah?arch=aarch64&distro=alpine-edge alpine buildah < 1.35.4-r0 alpine-edge aarch64
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...