SB2019101721 - Input validation error in containerd (Alpine package)
Published: October 17, 2019
Security Bulletin ID
SB2019101721
Severity
Medium
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Denial of service
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Input validation error (CVE-ID: CVE-2019-17596)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of DSA public keys in crypto/x509.Verify. A remote attacker can pass a specially crafted X.509 certificate chain to the application and perform a denial of service attack.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=573b7537c7e1ab2732007a1d026a913613ca2d03
- https://git.alpinelinux.org/aports/commit/?id=17caf1ca31bcf51f92d7f466d287824869ec3f25
- https://git.alpinelinux.org/aports/commit/?id=c64d2552678a7126d5e1d18ac54ea0ee126298d9
- https://git.alpinelinux.org/aports/commit/?id=c325c4cf49fc80b50d1eac10a708571fe54dd4a0
- https://git.alpinelinux.org/aports/commit/?id=3b2d519d19eed612aeaf0a62ee9003e23cbe7c2f
- https://git.alpinelinux.org/aports/commit/?id=d7b13c44a74649bc533f1d55da1a08319da4cfe4
- https://git.alpinelinux.org/aports/commit/?id=971e4b11222464f77b1bb47c32f4f1c83cd89d86
- https://git.alpinelinux.org/aports/commit/?id=3eda71ae2f9197704bc3b59f8ab7563f81cefb4d