Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2019-3387

Опубликовано: 14 нояб. 2019
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2019-3387: osinfo-db and libosinfo security and bug fix update (LOW)

gnome-boxes [3.28.5-7]

  • Bump the release to 3.28.5-7
  • Related: #1739897

[3.28.5-7]

  • Filter off unsupported architectures
  • Related: #1739897

[3.28.5-6]

  • Revert 'Add 3D acceleration option (powered by virgl)'
  • Related: #1647004

[3.28.5-5]

  • Add 3D acceleration option (powered by virgl)
  • Resolves: #1647004

[3.28.5-4]

  • Add rhel-8.0 logo & update logo for rhel-4.0 & update recommendations
  • Resolves: #1713130

libosinfo [1.5.0-3]

  • Resolves: rhbz#1727843 - CVE-2019-13313 libosinfo: osinfo-install-script option leaks password via command line argument

[1.5.0-2]

  • Resolves: rhbz#1712425 - New defects found in libosinfo-1.5.0-1.el8

[1.5.0-1]

  • Update to 1.5.0 release
  • Resolves: rhbz#1699988 - Rebase to the latest upstream release

osinfo-db [20190611-1.0.2]

  • add extra oracle osinfo files since upstream include others [Orabug: 30294515]

[20190611-1.0.1]

  • Sync oracle files with upstream and convert xml.in to xml [Orabug: 29855750]
  • add ol5 ol6 ol7 os type [Orabug: 27932947]
  • osinfo-query command error with OL7U5 [Orabug: 27700001]
  • Update OL7U5 osinfo-db to add OL7U5 release support [Orabug: 27700063]
  • add ol7.4 os info [Orabug: 27175558]
  • Update Oracle Linux OS info [Orabug: 26135475]
  • Add Oracle Linux OS info [Orabug: 18501468]
  • Pack ol.xml into tarball [Orabug: 20410527]
  • Update libosinfo to add all Oracle linux OS release/updates information [Orabug: 26135475]

[20190611-1]

  • Update to v20190611 release
  • Resolves: rhbz#1699990 - Rebase to the latest upstream release

[20190504-2]

  • Add rhel-8.1 & rhel-7.7 entry
  • Resolves: rhbz#1713245 - Add rhel-8.1 and rhel-7.7 entries

[20190504-1]

  • Update to v20190504 release
  • Resolves: rhbz#1699990 - Rebase to the latest upstream release
  • Resolves: rhbz#1689817 - virt-manager cannot detect operating system name for rhel8.0.0 tree automatically
  • Resolves: rhbz#1703480 - rhel8.0.x is not detected as rhel8.0
  • Resolves: rhbz#1685364 - Add win2019 to libosinfo

osinfo-db-tools [1.5.0-4]

  • Related: rhbz#1712426 - New defects found in osinfo-db-tools-1.5.0-2.el8

[1.5.0-3]

  • Resolves: rhbz#1712426 - New defects found in osinfo-db-tools-1.5.0-2.el8

[1.5.0-2]

  • Resolves: rhbz#1681879 - osinfo-db-tools changes blocked until gating tests are added

[1.5.0-1]

  • Update to 1.3.0 release
  • Resolves: rhbz#1699989 - Rebase to the latest upstream release

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

libosinfo

1.5.0-3.el8

osinfo-db

20190611-1.0.2.el8

osinfo-db-tools

1.5.0-4.el8

Oracle Linux x86_64

gnome-boxes

3.28.5-7.el8

libosinfo

1.5.0-3.el8

osinfo-db

20190611-1.0.2.el8

osinfo-db-tools

1.5.0-4.el8

Связанные CVE

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 6 лет назад

libosinfo 1.5.0 allows local users to discover credentials by listing a process, because credentials are passed to osinfo-install-script via the command line.

CVSS3: 2.8
redhat
больше 6 лет назад

libosinfo 1.5.0 allows local users to discover credentials by listing a process, because credentials are passed to osinfo-install-script via the command line.

CVSS3: 7.8
nvd
больше 6 лет назад

libosinfo 1.5.0 allows local users to discover credentials by listing a process, because credentials are passed to osinfo-install-script via the command line.

CVSS3: 7.8
debian
больше 6 лет назад

libosinfo 1.5.0 allows local users to discover credentials by listing ...

suse-cvrf
больше 1 года назад

Security update for libosinfo