Home Embedded Vulns General Vulns

CVE-2020-8945

HIGH 7.5

Our Analysis: General Purpose

Our model has classified this vulnerability as relevant to General Purpose Systems, helping your team prioritize efforts effectively.

Published Date February 12, 2020
Last Modified November 21, 2024
CVSS Vector Not Available

Description

The proglottis Go wrapper before 0.1.1 for the GPGME library has a use-after-free, as demonstrated by use for container image pulls by Docker or CRI-O. This leads to a crash or potential code execution during GPG signature verification.

Potentially Affected Vendors