CVE-2020-26213 – ktbs.dev/teler
Package
Manager: go
Name: ktbs.dev/teler
Vulnerable Version: >=0 <0.0.1
Severity
Level: Medium
CVSS v3.1: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
EPSS: 0.0039 pctl0.59253
Details
Denial-of-Service within Docker container ### Impact If you run teler inside a Docker container and encounter `errors.Exit` function, it will cause denial-of-service (`SIGSEGV`) because it doesn't get process ID and process group ID of teler properly to kills. ### Specific Go Packages Affected ktbs.dev/teler/pkg/errors ### Patches Upgrade to the >= 0.0.1 version. ### Workarounds N/A ### References - https://github.com/kitabisa/teler/commit/ec6082049dba9e44a21f35fb7b123d42ce1a1a7e ### For more information If you have any questions or comments about this advisory: * Open an issue in [Issues Section](https://github.com/kitabisa/teler/issues) * Email us at [infosec@kitabisa.com](mailto:infosec@kitabisa.com)
Metadata
Created: 2021-05-24T17:00:46Z
Modified: 2023-10-02T15:30:28Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/05/GHSA-jhj6-5mh6-4pvf/GHSA-jhj6-5mh6-4pvf.json
CWE IDs: ["CWE-476"]
Alternative ID: GHSA-jhj6-5mh6-4pvf
Finding: F002
Auto approve: 1