isula-build is a tool used for container images building.
Security Fix(es):
When using isula-build to build container images, some functions for processing external data do not remove spaces when processing data. This vulnerability can cause a program crash. The open-source software isula-build fuzzing test shows that when multiple spaces are added to the end of 'RUN' will cause a isula-builder panic, for example, RUN echo "hello" <space><space>..(CVE-2021-33629)
{
"severity": "Low"
}{
"src": [
"isula-build-0.9.5-6.oe1.src.rpm"
],
"aarch64": [
"isula-build-0.9.5-6.oe1.aarch64.rpm",
"isula-build-debuginfo-0.9.5-6.oe1.aarch64.rpm",
"isula-build-debugsource-0.9.5-6.oe1.aarch64.rpm"
],
"x86_64": [
"isula-build-debugsource-0.9.5-6.oe1.x86_64.rpm",
"isula-build-0.9.5-6.oe1.x86_64.rpm",
"isula-build-debuginfo-0.9.5-6.oe1.x86_64.rpm"
]
}