OESA-2023-1686
Dashboard / Vulnerabilities / OESA-2023-1686
OESA-2023-1686
Summary: iSulad security update
Details: Security Fix(es): When malicious images are pulled by isula pull, attackers can execute arbitrary code.(CVE-2021-33635) When the isula load command is used to load malicious images, attackers can execute arbitrary code.(CVE-2021-33636) When the isula export command is used to export a container to an image and the container is controlled by an attacker, the attacker can escape the container.(CVE-2021-33637) When the isula cp command is used to copy files from a container to a host machine and the container is controlled by an attacker, the attacker can escape the container.(CVE-2021-33638)
References: https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2023-1686, https://nvd.nist.gov/vuln/detail/CVE-2021-33635, https://nvd.nist.gov/vuln/detail/CVE-2021-33636, https://nvd.nist.gov/vuln/detail/CVE-2021-33637, https://nvd.nist.gov/vuln/detail/CVE-2021-33638
Affected packages
Package
Name: iSulad
Purl: pkg:rpm/openEuler/iSulad&distro=openEuler-20.03-LTS-SP1
Affected ranges
Type: ECOSYSTEM
Events:
