Comment on Vulnerabilities on Dockerhub

rtxn@lemmy.world ⁨2⁩ ⁨days⁩ ago

Debian is extremely diligent about fixing high-risk vulnerabilities. A high severity CVE does not mean that you are at severe risk. It’s more an indication of how fucked you can be IF the vulnerability is exploited to the greatest potential.

One of the CVEs affects libraw, which is a library for handling RAW photograph files. If a RAW file contains a particular header, and that header is maliciously constructed in a particular way, extracting an embedded thumbnail can allow the attacker to execute arbitrary code on the server. To make that happen, the attacker must already have access to the server to upload and process the file, which means that security has already failed.

The Swiss cheese model applies to cybersecurity too.

original
Sort:hotnewtop