Know every vulnerabilitybefore it knows you.
DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.
- Feiten
Microsoft heeft kwetsbaarheden verholpen in Mariner (Azure Linux).
- Interpretaties
De kwetsbaarheden betreffen oudere kwetsbaarheden in diverse subcomponenten van de distro, zoals Python, Emacs, Qemu, Django, Curl, wget etc. welke in de nieuwe versie zijn verholpen.
- Oplossingen
Microsoft heeft updates beschikbaar gesteld waarmee de beschreven kwetsbaarheden worden verholpen. We raden u aan om deze updates te installeren. Meer informatie over de kwetsbaarheden, de installatie van de updates en eventuele work-arounds vindt u op:
https://portal.msrc.microsoft.com/en-us/security-guidance
- Kans
medium
- Schade
high
- CWE-115
Misinterpretation of Input
- CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
- CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
- CWE-122
Heap-based Buffer Overflow
- CWE-125
Out-of-bounds Read
- CWE-129
Improper Validation of Array Index
- CWE-187
Partial String Comparison
- CWE-190
Integer Overflow or Wraparound
- CWE-191
Integer Underflow (Wrap or Wraparound)
- CWE-193
Off-by-one Error
- CWE-20
Improper Input Validation
- CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- CWE-269
Improper Privilege Management
- CWE-273
Improper Check for Dropped Privileges
- CWE-280
Improper Handling of Insufficient Permissions or Privileges
- CWE-295
Improper Certificate Validation
- CWE-297
Improper Validation of Certificate with Host Mismatch
- CWE-299
Improper Check for Certificate Revocation
- CWE-319
Cleartext Transmission of Sensitive Information
- CWE-362
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
- CWE-369
Divide By Zero
- CWE-371
CWE-371
- CWE-400
Uncontrolled Resource Consumption
- CWE-401
Missing Release of Memory after Effective Lifetime
- CWE-404
Improper Resource Shutdown or Release
- CWE-416
Use After Free
- CWE-444
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
- CWE-476
NULL Pointer Dereference
- CWE-532
Insertion of Sensitive Information into Log File
- CWE-667
Improper Locking
- CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
- CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
- CWE-770
Allocation of Resources Without Limits or Throttling
- CWE-772
Missing Release of Resource after Effective Lifetime
- CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
- CWE-787
Out-of-bounds Write
- CWE-833
Deadlock
- CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
- CWE-863
Incorrect Authorization
- CWE-918
Server-Side Request Forgery (SSRF)
- CWE-94
Improper Control of Generation of Code ('Code Injection')
- CWE-95
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')
Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.
Checkout DevGuard