Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2016-2781 | coreutils (CWE-20) #894

Open
yeyisan opened this issue Apr 26, 2022 · 4 comments
Open

CVE-2016-2781 | coreutils (CWE-20) #894

yeyisan opened this issue Apr 26, 2022 · 4 comments
Labels
bug Something isn't working KONDUKTO

Comments

@yeyisan
Copy link
Collaborator

yeyisan commented Apr 26, 2022

A low severity vulnerability has been discovered in your project.

Project Name: Node

Scanner Name: trivy

Cwe ID: 20

Cwe Name: Improper Input Validation

Cwe Link: https://cwe.mitre.org/data/definitions/20.html

CVE ID: CVE-2016-2781

Target: redis:latest (debian 11.3)

Packages:

  • coreutils : 8.32-4 - Fixed Version:

References:

Tool Description: chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer.

Custom Description: bbb

@yeyisan yeyisan added bug Something isn't working KONDUKTO labels Apr 26, 2022
@yeyisan yeyisan closed this as completed Apr 26, 2022
@yeyisan yeyisan added the wontfix This will not be worked on label Apr 26, 2022
@yeyisan
Copy link
Collaborator Author

yeyisan commented Apr 26, 2022

The issue has been closed by Kondukto since it is marked as won't fix.

@yeyisan yeyisan reopened this Apr 26, 2022
@yeyisan yeyisan removed the wontfix This will not be worked on label Apr 26, 2022
@yeyisan
Copy link
Collaborator Author

yeyisan commented Apr 26, 2022

The issue has been reopened by Kondukto since its won't fix status has been removed.

@yeyisan
Copy link
Collaborator Author

yeyisan commented Apr 26, 2022

test

@yeyisan
Copy link
Collaborator Author

yeyisan commented Apr 26, 2022

noonono

@yeyisan yeyisan reopened this Apr 26, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working KONDUKTO
Projects
None yet
Development

No branches or pull requests

1 participant