[ALAS2-2023-2339] Amazon Linux 2 2017.12 - ALAS2-2023-2339: important priority package update for nerdctl

Severity Important
Affected Packages 4
CVEs 2

Package updates are available for Amazon Linux 2 that fix the following vulnerabilities:
CVE-2023-39325:
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

ID
ALAS2-2023-2339
Severity
important
URL
https://alas.aws.amazon.com/AL2/ALAS-2023-2339.html
Published
2023-11-09T19:19:00
(10 months ago)
Modified
2023-11-15T21:10:00
(10 months ago)
Rights
Amazon Linux Security Team
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/amazonlinux/nerdctl?arch=x86_64&distro=amazonlinux-2 amazonlinux nerdctl < 1.6.2-1.amzn2.0.2 amazonlinux-2 x86_64
Affected pkg:rpm/amazonlinux/nerdctl?arch=aarch64&distro=amazonlinux-2 amazonlinux nerdctl < 1.6.2-1.amzn2.0.2 amazonlinux-2 aarch64
Affected pkg:rpm/amazonlinux/nerdctl-debuginfo?arch=x86_64&distro=amazonlinux-2 amazonlinux nerdctl-debuginfo < 1.6.2-1.amzn2.0.2 amazonlinux-2 x86_64
Affected pkg:rpm/amazonlinux/nerdctl-debuginfo?arch=aarch64&distro=amazonlinux-2 amazonlinux nerdctl-debuginfo < 1.6.2-1.amzn2.0.2 amazonlinux-2 aarch64
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...