Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:39350
HistoryFeb 19, 2023 - 8:35 p.m.

Denial Of Service (DoS)

2023-02-1920:35:42
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
24
containerd
vulnerability
onuntarjson
dos
attack
oci image

EPSS

0.001

Percentile

30.2%

github.com/containerd/containerd is vulnerable to Denial of Service (DoS). The vulnerability exists because the onUntarJSON function in importer.go does not properly limit the number of bytes read for specific files when importing an OCI image, allowing an attacker to cause an application crash through the maliciously crafted image.