Alpine Linux: From vulnerability... CVE-2017-9669,CVE-2017-9671

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

I’ve recently uncovered two critical vulnerabilities in Alpine Linux’s package manager, assigned CVE-2017-9669 and CVE-2017-9671. These vulnerabilities could potentially lead to an attacker executing malicious code on your machines, if you are using Alpine knowingly or implicitly. Alpine Linux is a lightweight Linux distribution that has become increasingly popular in the last several years. This was mainly possible thanks to its use within containers, notably in Docker. The majority of of the official Docker repositories have an alpine build variant, and the [alpine repository](https://hub.docker.com/_/alpine/) itself has more than 10 millions pulls at the time being. Alpine is advertised as a security-oriented distribution and its developers are putting a great deal of effort into living up to that claim, for instance, by including kernel side defense mechanisms and by compiling user space packages with all modern binary protections. For these reasons we use Alpine here at...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息