Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:22525
HistoryFeb 18, 2020 - 9:40 a.m.

Denial Of Service (DoS)

2020-02-1809:40:33
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
16

EPSS

0.001

Percentile

22.8%

github.com/containers/image is vulnerable to denial of service (DoS). The vulnerability exists because it does not restrict the sizes of blobs copied into memory such as the manifest, the config, signatures, etc, allowing an attacker to hijack registries leading to a big blobs and triggering an out of memory.