Debian Package Tracker
Register | Log in
Subscribe

golang-github-appc-cni

container network interface

Choose email to subscribe with

general
  • source: golang-github-appc-cni (main)
  • version: 0.8.1-1
  • maintainer: Debian Go Packaging Team (DMD)
  • uploaders: Dmitry Smirnov [DMD] – Tim Potter [DMD]
  • arch: all
  • std-ver: 4.5.1
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • oldstable: 0.3.0+dfsg-1
  • stable: 0.4.0+dfsg-1
  • testing: 0.8.1-1
  • unstable: 0.8.1-1
versioned links
  • 0.3.0+dfsg-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 0.4.0+dfsg-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 0.8.1-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • golang-github-appc-cni-dev
action needed
Problems while searching for a new upstream version high
uscan had problems while searching for a new upstream version:
In debian/watch no matching files for watch line
  https://github.com/containernetworking/cni/releases .*/archive/v?(\d[\d\.\-rc]+)\.tar\.gz
Created: 2021-03-20 Last update: 2021-04-15 12:06
1 security issue in stretch high

There is 1 open security issue in stretch.

1 important issue:
  • CVE-2021-20206: An improper limitation of path name flaw was found in containernetworking/cni in versions before 0.8.1. When specifying the plugin to load in the 'type' field in the network configuration, it is possible to use special elements such as "../" separators to reference binaries elsewhere on the system. This flaw allows an attacker to execute other existing binaries other than the cni plugins/types, such as 'reboot'. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Created: 2021-02-19 Last update: 2021-03-28 05:05
1 low-priority security issue in buster low

There is 1 open security issue in buster.

1 issue left for the package maintainer to handle:
  • CVE-2021-20206: (needs triaging) An improper limitation of path name flaw was found in containernetworking/cni in versions before 0.8.1. When specifying the plugin to load in the 'type' field in the network configuration, it is possible to use special elements such as "../" separators to reference binaries elsewhere on the system. This flaw allows an attacker to execute other existing binaries other than the cni plugins/types, such as 'reboot'. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

You can find information about how to handle this issue in the security team's documentation.

Created: 2021-02-19 Last update: 2021-03-28 05:05
news
[rss feed]
  • [2021-03-10] golang-github-appc-cni 0.8.1-1 MIGRATED to testing (Debian testing watch)
  • [2021-02-28] Accepted golang-github-appc-cni 0.8.1-1 (source) into unstable (Shengjing Zhu)
  • [2020-07-23] golang-github-appc-cni 0.8.0-2 MIGRATED to testing (Debian testing watch)
  • [2020-07-20] Accepted golang-github-appc-cni 0.8.0-2 (source) into unstable (Reinhard Tartler)
  • [2020-07-12] Accepted golang-github-appc-cni 0.8.0-1 (source) into experimental (Reinhard Tartler)
  • [2019-10-19] golang-github-appc-cni 0.7.1-2 MIGRATED to testing (Debian testing watch)
  • [2019-10-16] Accepted golang-github-appc-cni 0.7.1-2 (source) into unstable (Dmitry Smirnov)
  • [2019-09-26] Accepted golang-github-appc-cni 0.7.1-1 (source) into experimental (Dmitry Smirnov)
  • [2019-03-22] Accepted golang-github-appc-cni 0.7.0~rc2-1 (source) into experimental (Reinhard Tartler)
  • [2018-08-19] golang-github-appc-cni 0.4.0+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2018-08-17] Accepted golang-github-appc-cni 0.4.0+dfsg-1 (source) into unstable (Dmitry Smirnov)
  • [2016-06-25] golang-github-appc-cni 0.3.0+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2016-06-19] Accepted golang-github-appc-cni 0.3.0+dfsg-1 (source all) into unstable (Dmitry Smirnov)
  • [2016-05-27] golang-github-appc-cni 0.2.3+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2016-05-21] Accepted golang-github-appc-cni 0.2.3+dfsg-1 (source all) into unstable (Dmitry Smirnov)
  • [2016-04-09] golang-github-appc-cni 0.2.0~rc0+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2016-04-03] Accepted golang-github-appc-cni 0.2.0~rc0+dfsg-1 (source all) into unstable (Dmitry Smirnov)
  • [2016-03-28] golang-github-appc-cni 0.1.0+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2016-03-22] Accepted golang-github-appc-cni 0.1.0+dfsg-1 (source all) into unstable, unstable (Dmitry Smirnov)
bugs [bug history graph]
  • all: 0
links
  • homepage
  • lintian
  • buildd: logs, clang, reproducibility
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 0.8.0-2

Debian Package Tracker — Copyright 2013-2018 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing