Lucene search

K
vulnrichmentOpenEulerVULNRICHMENT:CVE-2021-33634
HistoryOct 29, 2023 - 7:51 a.m.

CVE-2021-33634 Malicious image running containers may cause DoS attacks

2023-10-2907:51:49
CWE-665
openEuler
github.com
3
cve-2021-33634
isulad
dos
malicious images

CVSS3

6.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H

AI Score

6.7

Confidence

Low

SSVC

Exploitation

none

Automatable

no

Technical Impact

partial

iSulad uses the lcr+lxc runtime (default) to run malicious images, which can cause DOS.

CVSS3

6.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H

AI Score

6.7

Confidence

Low

SSVC

Exploitation

none

Automatable

no

Technical Impact

partial

Related for VULNRICHMENT:CVE-2021-33634