UBUNTU-CVE-2022-1227
Dashboard / Vulnerabilities / UBUNTU-CVE-2022-1227
Summary:
Details: A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded by a potential victim, the vulnerability is triggered after a user runs the 'podman top' command. This action gives the attacker access to the host filesystem, leading to information disclosure or denial of service.
References: https://ubuntu.com/security/CVE-2022-1227, https://bugzilla.redhat.com/show_bug.cgi?id=2070368, https://github.com/containers/psgo/pull/92, https://github.com/containers/psgo/commit/d9467da9f563a9de1ece79dcae86b37b1db75443, https://www.cve.org/CVERecord?id=CVE-2022-1227
Affected packages
Package
Name: golang-github-containers-psgo
Purl: pkg:deb/ubuntu/golang-github-containers-psgo?arch=source&distro=focal
Affected ranges
Type: ECOSYSTEM
Events:
