Crun Project Crun 0.10.3

CPE Details

Crun Project Crun 0.10.3
0.10.3
2019-11-19
18h46 +00:00
2019-11-19
18h46 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:crun_project:crun:0.10.3:*:*:*:*:*:*:*

Informations

Vendor

crun_project

Product

crun

Version

0.10.3

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2022-27650 2022-04-04 17h45 +00:00 A flaw was found in crun where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers were started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs.
7.5
High
CVE-2019-18837 2019-11-13 19h01 +00:00 An issue was discovered in crun before 0.10.5. With a crafted image, it doesn't correctly check whether a target is a symlink, resulting in access to files outside of the container. This occurs in libcrun/linux.c and libcrun/chroot_realpath.c.
8.6
High