DirectorySecurity Advisories
Sign In
Security Advisories

CGA-m23h-26vh-86wf

Published

Last updated

https://images.chainguard.dev/security/CGA-m23h-26vh-86wf
Package

grype

Latest Update
Fixed
Fixed Version

0.74.4-r0

Aliases
  • CVE-2024-24579
  • GHSA-hpxr-w9w7-g4gv

Severity

5.3

Medium

CVSS V3

Summary

stereoscope vulnerable to tar path traversal when processing OCI tar archives

Description

Impact

It is possible to craft an OCI tar archive that, when stereoscope attempts to unarchive the contents, will result in writing to paths outside of the unarchive temporary directory. Specifically, use of github.com/anchore/stereoscope/pkg/file.UntarToDirectory() function, the github.com/anchore/stereoscope/pkg/image/oci.TarballImageProvider struct, or the higher level github.com/anchore/stereoscope/pkg/image.Image.Read() function express this vulnerability.

Patches

Patched in v0.0.1

Workarounds

If you are using the OCI archive as input into stereoscope then you can switch to using an OCI layout by unarchiving the tar archive and provide the unarchived directory to stereoscope.

References

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images