Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:22498
HistoryFeb 13, 2020 - 5:13 a.m.

Use After Free (UAF)

2020-02-1305:13:18
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12

0.012 Low

EPSS

Percentile

85.0%

github.com/proglottis/gpgme is vulnerable to use-after-free. The attack is possible because it allows malicious use for container image pulls by Docker or CRI-O, leading to an application crash or arbitrary code execution during GPG signature verification.