Lucene search

K
ubuntuUbuntuUSN-5628-2
HistorySep 22, 2022 - 12:00 a.m.

etcd vulnerabilities

2022-09-2200:00:00
ubuntu.com
79
etcd vulnerabilities
ubuntu 18.04 esm
denial of service
sensitive information
directory permissions
endpoint setup

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:N/I:N/A:P

CVSS3

7.7

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H

AI Score

7.5

Confidence

High

EPSS

0.001

Percentile

36.3%

Releases

  • Ubuntu 18.04 ESM

Packages

  • etcd - Transitional package for etcd-client and etcd-server

Details

USN-5628-1 fixed vulnerabilities in etcd.
This update provides the corresponding updates for Ubuntu 18.04 ESM.

Original advisory details:

It was discovered that etcd incorrectly handled certain specially crafted
WAL files. An attacker could possibly use this issue to cause a denial of
service. (CVE-2020-15106, CVE-2020-15112)

It was discovered that etcd incorrectly handled directory permissions when
trying to create a directory that exists already. An attacker could
possibly use this issue to obtain sensitive information. (CVE-2020-15113)

It was discovered that etcd incorrectly handled endpoint setup. An
attacker could possibly use this issue to cause a denial of
service. (CVE-2020-15114)

OSVersionArchitecturePackageVersionFilename
Ubuntu18.04noarchetcd-server<ย 3.2.17+dfsg-1ubuntu0.1~esm1UNKNOWN
Ubuntu18.04noarchetcd<ย 3.2.17+dfsg-1ubuntu0.1UNKNOWN
Ubuntu18.04noarchetcd-client<ย 3.2.17+dfsg-1ubuntu0.1UNKNOWN
Ubuntu18.04noarchetcd-server<ย 3.2.17+dfsg-1ubuntu0.1UNKNOWN
Ubuntu18.04noarchetcd-server-dbgsym<ย 3.2.17+dfsg-1ubuntu0.1UNKNOWN
Ubuntu18.04noarchgolang-etcd-server-dev<ย 3.2.17+dfsg-1ubuntu0.1UNKNOWN
Ubuntu18.04noarchetcd-client<ย 3.2.17+dfsg-1ubuntu0.1~esm1UNKNOWN
Ubuntu18.04noarchetcd<ย 3.2.17+dfsg-1ubuntu0.1~esm1UNKNOWN

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:N/I:N/A:P

CVSS3

7.7

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H

AI Score

7.5

Confidence

High

EPSS

0.001

Percentile

36.3%