First published: Wed Sep 15 2021(Updated: )
A highly-available key value store for shared configuration<br>Security Fix(es):<br><li> net/<a href="http:" target="_blank">http:</a> panic in ReadRequest and ReadResponse when reading a very large</li> header (CVE-2021-31525)<br><li> golang: net: lookup functions may return invalid host names (CVE-2021-33195)</li> <li> golang: net/http/httputil: ReverseProxy forwards connection headers if first one is empty (CVE-2021-33197)</li> <li> golang: math/big.Rat: may cause a panic or an unrecoverable fatal error if passed inputs with very large exponents (CVE-2021-33198)</li> For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE<br>page listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/etcd | <3.3.23-3.1.el8 | 3.3.23-3.1.el8 |
redhat/etcd-debuginfo | <3.3.23-3.1.el8 | 3.3.23-3.1.el8 |
redhat/etcd-debugsource | <3.3.23-3.1.el8 | 3.3.23-3.1.el8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.