CVE-2021-33636
29.10.2023, 08:15
When the isula load command is used to load malicious images, attackers can execute arbitrary code.
Vendor | Product | Version |
---|---|---|
openeuler | isula | 2.0.8-20210518.144540 |
openeuler | isula | 2.0.18-10 |
openeuler | isula | 2.1.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-665 - Improper InitializationThe software does not initialize or incorrectly initializes a resource, which might leave the resource in an unexpected state when it is accessed or used.
- CWE-94 - Improper Control of Generation of Code ('Code Injection')The software constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
References