SB2020020732 - Spoofing attack in containerd (Alpine package)



SB2020020732 - Spoofing attack in containerd (Alpine package)

Published: February 7, 2020 Updated: May 7, 2023

Security Bulletin ID SB2020020732
Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Spoofing attack (CVE-ID: CVE-2020-0601)

The vulnerability allows a remote attacker to perform spoofing attack.

The vulnerability exists due to the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates. A remote attacker can use a spoofed code-signing certificate to sign a malicious executable, make it appear the file was from a trusted, legitimate source, trick a victim to open it and gain access to sensitive information.

A successful exploit could also allow the attacker to conduct man-in-the-middle attacks and decrypt confidential information on user connections to the affected software.

Updated
According to VirusTotal, there is in the wild exploitation of his vulnerability as of January 17, 2020.

Remediation

Install update from vendor's website.