CVE-2021-33635: Pull malicious images may cause process to be hijacked
Published Oct 29, 2023
·Updated
When malicious images are pulled by isula pull, attackers can execute arbitrary code.
Affected Software
3 affected components
Openeuler Isula=2.0.8-20210518.144540
Openeuler Isula=2.0.18-10
Openeuler Isula=2.1.2
Remediation
Patch Available
Patch Available
Event History
Oct 29, 2023
CVE Published
07:56 AM
Data Sourced
07:56 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-33635.
2
What is the severity of CVE-2021-33635?
The severity of CVE-2021-33635 is critical with a severity score of 9.8.
3
Which software versions are affected by CVE-2021-33635?
Openeuler Isula versions 2.0.8-20210518.144540, 2.0.18-10, and 2.1.2 are affected.
4
How can the vulnerability CVE-2021-33635 be exploited?
The vulnerability CVE-2021-33635 can be exploited by pulling malicious images using isula pull, which allows attackers to execute arbitrary code.
5
How can I fix CVE-2021-33635?
To fix CVE-2021-33635, it is recommended to update Openeuler Isula to a version that is not affected by the vulnerability. Please refer to the provided references for more information.