apko 允许用户构建并发布由 APK 软件包生成的 OCI 容器镜像。在 0.2.0 至 1.4.5 版本之前, 模块中的 和 函数在处理 和 条目中的 UID 和 GID 字段时,使用了 将其转换为 类型,但未进行范围检查。在 64 位平台上,超出范围的数值(例如 4294967296,即 2^32)会被截断为 0,而负数值则会发生回绕(wrap-around)。 由于 apko 会解析其所安装软件包提供的 passwd 和 group 条目,并将其写回镜像中,因此,如果攻击者控制了某个被安装到镜像中的软件包,
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| chainguard-dev | apko | 0.2.0 ~ 1.4.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet