GO-2022-0921
Dashboard / Vulnerabilities / GO-2022-0921
Summary: Archive package allows chmod of file outside of unpack target directory in github.com/containerd/containerd
Details: Archive package allows chmod of file outside of unpack target directory in github.com/containerd/containerd
References: https://github.com/containerd/containerd/security/advisories/GHSA-c72p-9xmj-rx3w, https://nvd.nist.gov/vuln/detail/CVE-2021-32760, https://github.com/containerd/containerd/commit/22e9a70c71eff6507be71955947a611f2ed91e6c, https://github.com/containerd/containerd/commit/7ad08c69e09ee4930a48dbf2aab3cd612458617f, https://github.com/containerd/containerd/releases/tag/v1.4.8, https://github.com/containerd/containerd/releases/tag/v1.5.4, https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DDMNDPJJTP3J5GOEDB66F6MGXUTRG3Y3, https://lists.fedoraproject.org/archives/list/[email protected]/message/DDMNDPJJTP3J5GOEDB66F6MGXUTRG3Y3, https://security.gentoo.org/glsa/202401-31
Affected packages
Package
Name: github.com/containerd/containerd
Purl: pkg:golang/github.com/containerd/containerd
Affected ranges
Type: SEMVER
Events:
