Package Search Help

You can use boolean logic (e.g. AND/OR/NOT) for complex search queries. For more help and examples, see the search documentation.

Search by package name:
my-package (implicit)
name:my-package (explicit)

Search by package filename:
filename:my-package.ext 

Search by package tag:
tag:latest 

Search by package version:
version:1.0.0  prerelease:true (prereleases)
prerelease:false (no prereleases)

Search by package architecture:
architecture:x86_64 

Search by package distribution:
distribution:el 

Search by package license:
license:MIT 

Search by package format:
format:deb 

Search by package status:
status:in_progress 

Search by package file checksum:
checksum:5afba 

Search by package security status:
severity:critical 

Search by package vulnerabilities:
vulnerabilities:>1 
vulnerabilities:<1000 

Search by # of package downloads:
downloads:>8 
downloads:<100 

Search by package type:
type:binary 
type:source 

Search by package size (bytes):
size:>50000 
size:<10000 

Search by dependency name/version:
dependency:log4j 
dependency:log4j=1.0.0 
dependency:log4j>1.0.0 

Search by uploaded date:
uploaded:>"1 day ago" 
uploaded:<"August 14, 2022 EST" 

Search by entitlement token (identifier):
entitlement:3lKPVJPosCsY 

Search by policy violation:
policy_violated:true
deny_policy_violated:true
license_policy_violated:true
vulnerability_policy_violated:true

Search by repository:
repository:repo-name

Search by last download date:
last_downloaded:<"30 days ago" 
last_downloaded:>"August 14, 2022 EST" 

Search queries for all Debian-specific (and related) package types

Search by component:
deb_component:unstable

Search queries for all Maven-specific (and related) package types

Search by group ID:
maven_group_id:org.apache

Search queries for all Docker-specific (and related) package types

Search by image digest:
docker_image_digest:sha256:7c5..6d4
(full hashref only)

Search by layer digest:
docker_layer_digest:sha256:4c4..ae4
(full hashref only)

Search queries for all Generic-specific package types

Search by file path:
generic_filepath:path/to/file.txt

Search by directory:
generic_directory:path/to

Field type modifiers (depending on the type, you can influence behaviour)

For all queries, you can use:
~foo for negation

For string queries, you can use:
^foo to anchor to start of term
foo$ to anchor to end of term
foo*bar for fuzzy matching

For number/date or version queries, you can use:
>foo for values greater than
>=foo for values greater / equal
<foo for values less than
<=foo for values less / equal

Need a secure and centralised artifact repository to deliver Alpine, Cargo, CocoaPods, Composer, Conan, Conda, CRAN, Dart, Debian, Docker, Generic, Go, Helm, Hex, HuggingFace, LuaRocks, Maven, MCP, npm, NuGet, P2, Python, RedHat, Ruby, Swift, Terraform, Vagrant, VSX, Raw & More packages?

Cloudsmith is the new standard in Package / Artifact Management and Software Distribution.

With support for all major package formats, you can trust us to manage your software supply chain.

Start My Free Trial
 Public tetrate tetrate (Tetrate) / getistio-containers
Tetrate Istio Distro project (formerly GetIstio) container images registry

Docker logo proxyv2  55ee31e11f1c951aef184e3c00c…

One-liner (summary)

A certifiably-awesome package curated by Bender Rodriguez, hosted by Cloudsmith.

Description

A certifiably-awesome package curated by Bender Rodriguez, hosted by Cloudsmith.

License

Unknown

Size

137.4 MB

Downloads

27675

Tags

image arm64 linux

Status  Completed
Checksum (MD5) 0c5b20518636c4c677ff602885a0d802
Checksum (SHA-1) ea566e522c5b5799f13ce71e1cf3b15bfaa735a1
Checksum (SHA-256) 55ee31e11f1c951aef184e3c00cfc41ce8ab5914a3045f3483797511dd16351d
Checksum (SHA-512) 03e31f24382021891eb64bc7fee49a3a4d4c09c5740ca99463405fd39a7a1194a9…
GPG Signature
GPG Fingerprint 7490c226a7c21a19bb1d09e800b3a57eef287d7b
Storage Region  Dublin, Ireland
Type  Binary (contains binaries and binary artifacts)
Uploaded At 3 months, 3 weeks ago
Uploaded By tetrate-ci
Slug Id proxyv2-q0fb
Unique Id BQML5XO5CLzm
Version (Raw) 55ee31e11f1c951aef184e3c00cfc41ce8ab5914a3045f3483797511dd16351d
Version (Parsed)
  • Type: Unknown
  docker-specific metadata
Image Digest sha256:55ee31e11f1c951aef184e3c00cfc41ce8ab5914a3045f3483797511dd16351d
Config Digest sha256:cc403d5684596bd6c4efe71f30e3cbb248676cf177f70932e255874837fd9877
V1 OCI Index Digest sha256:927a33b1be88f1ed6fb3df63810b15e147cf93d2a604148deae46f81378a88fe
V1 Distribution (Signed) Digest sha256:f8aa18e0acf8eca9fba3bd8c295d3394c38901f729e437f83d3bf82a946cc922
V1 OCI Digest sha256:7f8bf1b9afb350f213ea1505cc17a05a9f57348952600cf328a637a30964686c
V2 Distribution List Digest sha256:258211e6309ea4475ec8daf6869a91ccc2a8a737463c60d9a883f693083baa6d
V1 Distribution Digest sha256:e9490be750a8a879062167c4fa0a8f631a962c0d3b3ed4ab8c08b1e2e022214b
V2 Distribution Digest sha256:55ee31e11f1c951aef184e3c00cfc41ce8ab5914a3045f3483797511dd16351d
  extended metadata
Manifest Type V2 Distribution
Architecture arm64
Config
Created 2026-03-20 22:33:36 UTC
Os linux

This package was uploaded with the following V2 Distribution manifest:

{"schemaVersion":2,"mediaType":"application/vnd.docker.distribution.manifest.v2+json","config":{"mediaType":"application/vnd.docker.container.image.v1+json","size":4927,"digest":"sha256:0a846089c0e1d12ba3092d25c813547ae0033ac7a7b52f746fbc2ddcfd834153"},"layers":[{"mediaType":"application/vnd.docker.image.rootfs.diff.tar.gzip","size":32782128,"digest":"sha256:68b17bfc5ebe9347bb6695ca06e281e97d77528c51cf94b4898c03a7045b1b1e"},{"mediaType":"application/vnd.docker.image.rootfs.diff.tar.gzip","size":47267676,"digest":"sha256:4e44c9dc368d36299e27c2e2e2ce592688c3b25514b94c9861cfbe998f648b6a"},{"mediaType":"application/vnd.docker.image.rootfs.diff.tar.gzip","size":10948625,"digest":"sha256:369347a28705307ae5c4d356651dfac515210616f2a0d46a4611e343f7ff3d2c"},{"mediaType":"application/vnd.docker.image.rootfs.diff.tar.gzip","size":4928,"digest":"sha256:2837c2189740fe5b137cb0a326d3207ee46136c4cfbd1469dc52de48ef734e21"},{"mediaType":"application/vnd.docker.image.rootfs.diff.tar.gzip","size":5211,"digest":"sha256:245d9467edd5c2a2e9be3b502fd9a82afb38080201e95e2af722613114958ef0"},{"mediaType":"application/vnd.docker.image.rootfs.diff.tar.gzip","size":43544308,"digest":"sha256:94f3711eacc4e6bd08687f715e11d4bc5f30ad4053d751f26332f11142cfa8be"},{"mediaType":"application/vnd.docker.image.rootfs.diff.tar.gzip","size":9514238,"digest":"sha256:e6b4943aa5cc9d3d68716e996e24a671d3160f01b18b1d7492434c6ae73e50dd"}]}
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) ARG RELEASE
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) ARG LAUNCHPAD_BUILD_ARCH
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) LABEL org.opencontainers.image.ref.name=ubuntu
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) LABEL org.opencontainers.image.version=24.04
32 bytes
Digest: sha256:68b17bfc5ebe9347bb6695ca06e281e97d77528c51cf94b4898c03a7045b1b1e
Command: /bin/sh -c #(nop) ADD file:25d708bf0b30ddee20c0b2764034e065aca922cafd48eb9c662e35ba02ccf1de in /
31.3 MB
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) CMD ["/bin/bash"]
32 bytes
Digest: sha256:4e44c9dc368d36299e27c2e2e2ce592688c3b25514b94c9861cfbe998f648b6a
Command: RUN /bin/sh -c apt update && apt upgrade -y # buildkit
45.1 MB
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ENV DEBIAN_FRONTEND=noninteractive
32 bytes
Digest: sha256:369347a28705307ae5c4d356651dfac515210616f2a0d46a4611e343f7ff3d2c
Command: RUN /bin/sh -c apt-get update && apt-get install --no-install-recommends -y ca-certificates curl iptables nftables iproute2 iputils-ping knot-dnsutils netcat-openbsd tcpdump conntrack bsdmainutils net-tools lsof sudo && update-ca-certificates && apt-get upgrade -y && apt-get clean && rm -rf /var/log/*log /var/lib/apt/lists/* /var/log/apt/* /var/lib/dpkg/*-old /var/cache/debconf/*-old && update-alternatives --set iptables /usr/sbin/iptables-legacy && update-alternatives --set ip6tables /usr/sbin/ip6tables-legacy # buildkit
10.4 MB
Digest: sha256:2837c2189740fe5b137cb0a326d3207ee46136c4cfbd1469dc52de48ef734e21
Command: RUN /bin/sh -c useradd -m --uid 1337 istio-proxy && echo "istio-proxy ALL=NOPASSWD: ALL" >> /etc/sudoers # buildkit
4.8 KB
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: WORKDIR /
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ARG proxy_version
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ARG SIDECAR=envoy
32 bytes
Digest: sha256:245d9467edd5c2a2e9be3b502fd9a82afb38080201e95e2af722613114958ef0
Command: COPY envoy_bootstrap.json /var/lib/istio/envoy/envoy_bootstrap_tmpl.json # buildkit
5.1 KB
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ARG TARGETARCH
32 bytes
Digest: sha256:94f3711eacc4e6bd08687f715e11d4bc5f30ad4053d751f26332f11142cfa8be
Command: COPY arm64/envoy /usr/local/bin/envoy # buildkit
41.5 MB
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ENV ISTIO_META_ISTIO_PROXY_SHA=fca9ef956bd748bedb43d4c381af3d498dcf0723
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ARG TARGETARCH
32 bytes
Digest: sha256:e6b4943aa5cc9d3d68716e996e24a671d3160f01b18b1d7492434c6ae73e50dd
Command: COPY arm64/pilot-agent /usr/local/bin/pilot-agent # buildkit
9.1 MB
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ENTRYPOINT ["/usr/local/bin/pilot-agent"]
32 bytes
Docker logo
proxyv2
image arm64 linux
1 tetrate-ci
Docker logo
proxyv2
image amd64 linux
1 tetrate-ci
Docker logo
proxyv2
image amd64 linux
1 tetrate-ci
Docker logo
proxyv2
image arm64 linux
1 tetrate-ci
Docker logo
proxyv2
image amd64 linux
56 tetrate-ci
Docker logo
proxyv2
image arm64 linux
19 tetrate-ci
Docker logo
proxyv2
image amd64 linux
1 tetrate-ci
Docker logo
proxyv2
image arm64 linux
1 tetrate-ci
Docker logo
proxyv2
image arm64 linux
20 tetrate-ci
Docker logo
proxyv2
image arm64 linux
1 tetrate-ci
Docker logo
proxyv2
image arm64 linux
27675 tetrate-ci
Docker logo
proxyv2
new image amd64 linux
59.5 MB 8 hours ago
0 tetrate-ci
Docker logo
proxyv2
new image arm64 linux
57.8 MB 8 hours ago
0 tetrate-ci
Docker logo
proxyv2
new image arm64 linux
132.7 MB 8 hours ago
0 tetrate-ci
Docker logo
proxyv2
new image amd64 linux
56.6 MB 13 hours ago
0 tetrate-ci
Docker logo
proxyv2
new image amd64 linux
130.4 MB 14 hours ago
1 tetrate-ci
Docker logo
proxyv2
new image arm64 linux
130.8 MB 14 hours ago
1 tetrate-ci
Docker logo
proxyv2
new image arm64 linux
54.5 MB 15 hours ago
0 tetrate-ci
Docker logo
proxyv2
new image amd64 linux
128.8 MB 16 hours ago
0 tetrate-ci
Docker logo
proxyv2
image amd64 linux
20 tetrate-ci

Last scanned

3 months, 3 weeks ago

Scan result

Vulnerable

Vulnerability count

12

Max. severity

Medium
Target: BQML5XO5CLzm.sbom-cyclonedx.json (ubuntu 24.04)
MEDIUM

CVE-2025-68972: gnupg: GnuPG: Signature bypass via form feed character in signed messages

In GnuPG through 2.4.8, if a signed message has \f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the modified message succeeds (although an "invalid armor" message is printed during verification). This is related to use of \f as a marker to denote truncation of a long plaintext line.

Package Name: gpgv
Installed Version: 2.4.4-2ubuntu17.4
Fixed Version:

References: access.redhat.com gpg.fail media.ccc.de news.ycombinator.com nvd.nist.gov www.cve.org
MEDIUM

CVE-2026-22185: OpenLDAP: OpenLDAP LMDB: Denial of Service and Information Disclosure via Heap Buffer Underflow

OpenLDAP Lightning Memory-Mapped Database (LMDB) versions up to and including 0.9.14, prior to commit 8e1fda8, contain a heap buffer underflow in the readline() function of mdb_load. When processing malformed input containing an embedded NUL byte, an unsigned offset calculation can underflow and cause an out-of-bounds read of one byte before the allocated heap buffer. This can cause mdb_load to crash, leading to a limited denial-of-service condition.

Package Name: liblmdb0
Installed Version: 0.9.31-1build1
Fixed Version:

References: access.redhat.com bugs.openldap.org nvd.nist.gov seclists.org seclists.org www.cve.org www.openldap.org www.vulncheck.com
MEDIUM

CVE-2025-8941: linux-pam: Incomplete fix for CVE-2025-6020

A flaw was found in linux-pam. The pam_namespace module may improperly handle user-controlled paths, allowing local users to exploit symlink attacks and race conditions to elevate their privileges to root. This CVE provides a "complete" fix for CVE-2025-6020.

Package Name: libpam-modules
Installed Version: 1.5.3-5ubuntu5.5
Fixed Version:

References: access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com cve.mitre.org cve.mitre.org errata.almalinux.org errata.rockylinux.org linux.oracle.com linux.oracle.com nvd.nist.gov www.cve.org
MEDIUM

CVE-2025-8941: linux-pam: Incomplete fix for CVE-2025-6020

A flaw was found in linux-pam. The pam_namespace module may improperly handle user-controlled paths, allowing local users to exploit symlink attacks and race conditions to elevate their privileges to root. This CVE provides a "complete" fix for CVE-2025-6020.

Package Name: libpam-modules-bin
Installed Version: 1.5.3-5ubuntu5.5
Fixed Version:

References: access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com cve.mitre.org cve.mitre.org errata.almalinux.org errata.rockylinux.org linux.oracle.com linux.oracle.com nvd.nist.gov www.cve.org
MEDIUM

CVE-2025-8941: linux-pam: Incomplete fix for CVE-2025-6020

A flaw was found in linux-pam. The pam_namespace module may improperly handle user-controlled paths, allowing local users to exploit symlink attacks and race conditions to elevate their privileges to root. This CVE provides a "complete" fix for CVE-2025-6020.

Package Name: libpam-runtime
Installed Version: 1.5.3-5ubuntu5.5
Fixed Version:

References: access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com cve.mitre.org cve.mitre.org errata.almalinux.org errata.rockylinux.org linux.oracle.com linux.oracle.com nvd.nist.gov www.cve.org
MEDIUM

CVE-2025-8941: linux-pam: Incomplete fix for CVE-2025-6020

A flaw was found in linux-pam. The pam_namespace module may improperly handle user-controlled paths, allowing local users to exploit symlink attacks and race conditions to elevate their privileges to root. This CVE provides a "complete" fix for CVE-2025-6020.

Package Name: libpam0g
Installed Version: 1.5.3-5ubuntu5.5
Fixed Version:

References: access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com cve.mitre.org cve.mitre.org errata.almalinux.org errata.rockylinux.org linux.oracle.com linux.oracle.com nvd.nist.gov www.cve.org
MEDIUM

CVE-2026-3731: libssh: libssh: Denial of Service via out-of-bounds read in SFTP extension name handler

A weakness has been identified in libssh up to 0.11.3. The impacted element is the function sftp_extensions_get_name/sftp_extensions_get_data of the file src/sftp.c of the component SFTP Extension Name Handler. Executing a manipulation of the argument idx can lead to out-of-bounds read. The attack may be performed from remote. Upgrading to version 0.11.4 and 0.12.0 is sufficient to resolve this issue. This patch is called 855a0853ad3abd4a6cd85ce06fce6d8d4c7a0b60. You should upgrade the affected component.

Package Name: libssh-4
Installed Version: 0.10.6-2ubuntu0.3
Fixed Version: 0.10.6-2ubuntu0.4

References: access.redhat.com gitlab.com nvd.nist.gov ubuntu.com vuldb.com vuldb.com vuldb.com www.cve.org www.libssh.org www.libssh.org
MEDIUM

CVE-2025-45582: tar: Tar path traversal

GNU Tar through 1.35 allows file overwrite via directory traversal in crafted TAR archives, with a certain two-step process. First, the victim must extract an archive that contains a ../ symlink to a critical directory. Second, the victim must extract an archive that contains a critical file, specified via a relative pathname that begins with the symlink name and ends with that critical file's name. Here, the extraction follows the symlink and overwrites the critical file. This bypasses the protection mechanism of "Member name contains '..'" that would occur for a single TAR archive that attempted to specify the critical file via a ../ approach. For example, the first archive can contain "x -> ../../../../../home/victim/.ssh" and the second archive can contain x/authorized_keys. This can affect server applications that automatically extract any number of user-supplied TAR archives, and were relying on the blocking of traversal. This can also affect software installation processes in which "tar xf" is run more than once (e.g., when installing a package can automatically install two dependencies that are set up as untrusted tarballs instead of official packages). NOTE: the official GNU Tar manual has an otherwise-empty directory for each "tar xf" in its Security Rules of Thumb; however, third-party advice leads users to run "tar xf" more than once into the same directory.

Package Name: tar
Installed Version: 1.35+dfsg-3build1
Fixed Version:

References: www.openwall.com access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com cve.mitre.org errata.almalinux.org errata.rockylinux.org github.com linux.oracle.com linux.oracle.com lists.gnu.org nvd.nist.gov www.cve.org www.gnu.org www.gnu.org www.gnu.org www.gnu.org
LOW

CVE-2016-2781: coreutils: Non-privileged session can escape to the parent session in chroot

chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer.

Package Name: coreutils
Installed Version: 9.4-3ubuntu6.1
Fixed Version:

References: seclists.org www.openwall.com www.openwall.com access.redhat.com lists.apache.org lore.kernel.org mirrors.edge.kernel.org nvd.nist.gov www.cve.org
LOW

CVE-2022-3219: gnupg: denial of service issue (resource consumption) using compressed packets

GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB.

Package Name: gpgv
Installed Version: 2.4.4-2ubuntu17.4
Fixed Version:

References: access.redhat.com bugzilla.redhat.com dev.gnupg.org dev.gnupg.org marc.info nvd.nist.gov security.netapp.com www.cve.org
LOW

CVE-2025-29481: libbpf: Heap Buffer Overflow in libbpf

Buffer Overflow vulnerability in libbpf 1.5.0 allows a local attacker to execute arbitrary code via the bpf_object__init_prog` function of libbpf. This has been disputed by third parties who assert that "no one in their sane mind should be passing untrusted ELF files into libbpf while running under root."

Package Name: libbpf1
Installed Version: 1:1.3.0-2build2
Fixed Version:

References: access.redhat.com github.com nvd.nist.gov www.cve.org
LOW

CVE-2025-1352: elfutils: GNU elfutils eu-readelf libdw_alloc.c __libdw_thread_tail memory corruption

A vulnerability has been found in GNU elfutils 0.192 and classified as critical. This vulnerability affects the function __libdw_thread_tail in the library libdw_alloc.c of the component eu-readelf. The manipulation of the argument w leads to memory corruption. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is 2636426a091bd6c6f7f02e49ab20d4cdc6bfc753. It is recommended to apply a patch to fix this issue.

Package Name: libelf1t64
Installed Version: 0.190-1.1ubuntu0.1
Fixed Version:

References: access.redhat.com nvd.nist.gov sourceware.org sourceware.org sourceware.org vuldb.com vuldb.com vuldb.com www.cve.org www.gnu.org
LOW

CVE-2025-1376: elfutils: GNU elfutils eu-strip elf_strptr.c elf_strptr denial of service

A vulnerability classified as problematic was found in GNU elfutils 0.192. This vulnerability affects the function elf_strptr in the library /libelf/elf_strptr.c of the component eu-strip. The manipulation leads to denial of service. It is possible to launch the attack on the local host. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is b16f441cca0a4841050e3215a9f120a6d8aea918. It is recommended to apply a patch to fix this issue.

Package Name: libelf1t64
Installed Version: 0.190-1.1ubuntu0.1
Fixed Version:

References: access.redhat.com nvd.nist.gov sourceware.org sourceware.org sourceware.org vuldb.com vuldb.com vuldb.com www.cve.org www.gnu.org
LOW

CVE-2024-2236: libgcrypt: vulnerable to Marvin Attack

A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-style attack, which can lead to the decryption of RSA ciphertexts.

Package Name: libgcrypt20
Installed Version: 1.10.3-2build1
Fixed Version:

References: access.redhat.com access.redhat.com access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com bugzilla.redhat.com cve.mitre.org dev.gnupg.org errata.almalinux.org errata.rockylinux.org github.com gitlab.com linux.oracle.com linux.oracle.com lists.gnupg.org nvd.nist.gov www.cve.org
LOW

CVE-2024-56433: shadow-utils: Default subordinate ID configuration in /etc/login.defs could lead to compromise

shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid.

Package Name: login
Installed Version: 1:4.13+dfsg1-4ubuntu3.2
Fixed Version:

References: access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com cve.mitre.org errata.almalinux.org errata.rockylinux.org github.com github.com github.com linux.oracle.com linux.oracle.com nvd.nist.gov www.cve.org
LOW

CVE-2024-56433: shadow-utils: Default subordinate ID configuration in /etc/login.defs could lead to compromise

shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid.

Package Name: passwd
Installed Version: 1:4.13+dfsg1-4ubuntu3.2
Fixed Version:

References: access.redhat.com access.redhat.com bugzilla.redhat.com bugzilla.redhat.com cve.mitre.org errata.almalinux.org errata.rockylinux.org github.com github.com github.com linux.oracle.com linux.oracle.com nvd.nist.gov www.cve.org

These instructions assume you have setup the repository first (or read it).

To pull proxyv2 @ reference/tag sha256:55ee31e11f1c951aef184e3c00cfc41ce8ab5914a3045f3483797511dd16351d:

docker pull containers.istio.tetratelabs.com/proxyv2@sha256:55ee31e11f1c951aef184e3c00cfc41ce8ab5914a3045f3483797511dd16351d

You can also pull the latest version of this image (if it exists):

docker pull containers.istio.tetratelabs.com/proxyv2:latest

To refer to this image after pulling in a Dockerfile, specify the following:

FROM containers.istio.tetratelabs.com/proxyv2@sha256:55ee31e11f1c951aef184e3c00cfc41ce8ab5914a3045f3483797511dd16351d
Top