GO-2020-0007
Dashboard / Vulnerabilities / GO-2020-0007
GO-2020-0007
Published: 14 Apr 2021Last Modified: 20 May 2024
Aliases:
Summary: Improper input validation in github.com/seccomp/libseccomp-golang
Details: Filters containing rules with multiple syscall arguments are improperly constructed, such that all arguments are required to match rather than any of the arguments (AND is used rather than OR). These filters can be bypassed by only specifying a subset of the arguments due to this behavior.
References: https://github.com/seccomp/libseccomp-golang/commit/06e7a29f36a34b8cf419aeb87b979ee508e58f9e
Affected packages
Package
Name: github.com/seccomp/libseccomp-golang
Purl: pkg:golang/github.com/seccomp/libseccomp-golang
Affected ranges
Type: SEMVER
Events:
Introduced- 0
Fixed -0.9.1-0.20170424173420-06e7a29f36a3
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
