Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.1.2.2022.1820
Category:Huawei EulerOS Local Security Checks
Title:Huawei EulerOS: Security Advisory for docker-engine (EulerOS-SA-2022-1820)
Summary:The remote host is missing an update for the Huawei EulerOS 'docker-engine' package(s) announced via the EulerOS-SA-2022-1820 advisory.
Description:Summary:
The remote host is missing an update for the Huawei EulerOS 'docker-engine' package(s) announced via the EulerOS-SA-2022-1820 advisory.

Vulnerability Insight:
containerd is a container runtime available as a daemon for Linux and Windows.A bug was found in containerd prior to versions 1.6.1,1.5.10, and 1.14.12 where containers launched through containerd's CRI implementation on Linux with a specially-crafted image configuration could gain access to read-only copies of arbitrary files and directories on the host.This may bypass any policy-based enforcement on container setup (including a Kubernetes Pod Security Policy) and expose potentially sensitive information.Kubernetes and crictl can both be configured to use containerd's CRI implementation.This bug has been fixed in containerd 1.6.1, 1.5.10,and 1.4.12. Users should update to these versions to resolve the issue.(CVE-2022-23648)

Affected Software/OS:
'docker-engine' package(s) on Huawei EulerOS V2.0SP10(x86_64).

Solution:
Please install the updated package(s).

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2022-23648
https://github.com/containerd/containerd/security/advisories/GHSA-crp2-qrr5-8pq7
Debian Security Information: DSA-5091 (Google Search)
https://www.debian.org/security/2022/dsa-5091
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AUDQUQBZJGBWJPMRVB6QCCCRF7O3O4PA/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HFTS2EF3S7HNYSNZSEJZIJHPRU7OPUV3/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OCCARJ6FU4MWBTXHZNMS7NELPDBIX2VO/
https://security.gentoo.org/glsa/202401-31
http://packetstormsecurity.com/files/166421/containerd-Image-Volume-Insecure-Handling.html
https://github.com/containerd/containerd/commit/10f428dac7cec44c864e1b830a4623af27a9fc70
https://github.com/containerd/containerd/releases/tag/v1.4.13
https://github.com/containerd/containerd/releases/tag/v1.5.10
https://github.com/containerd/containerd/releases/tag/v1.6.1
CopyrightCopyright (C) 2022 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.