Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2020-1379

Опубликовано: 15 апр. 2020
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2020-1379: container-tools:ol8 security and bug fix update (IMPORTANT)

buildah [1.11.6-6.0.1]

  • Fixes troubles with oracle registry login [Orabug: 29937283]

[1.11.6-6]

  • fix COPY command takes long time with buildah
  • Resolves: #1806119

[1.11.6-5]

  • fix Podman support for FIPS Mode requires a bind mount inside the container
  • Resolves: #1804188

cockpit-podman [11-1]

  • Fix Alert notification in Image Search Modal
  • Allow more than a single Error Notification for Container action errors
  • Various Alert cleanups
  • Translation updates
  • Related: RHELPLAN-25138

[10-1]

  • Support for user containers
  • Show list of containers that use given image
  • Show placeholder while loading containers and images
  • Fix setting memory limit - bug 1732713
  • Add container Terminal - bug 1703245
  • Related: RHELPLAN-25138

conmon [2:2.0.6-1]

  • update to 2.0.6
  • Related: RHELPLAN-25138

[2:2.0.5-1]

  • update to 2.0.5
  • Related: RHELPLAN-25138

[2:2.0.4-1]

  • update to 2.0.4 bugfix release
  • Related: RHELPLAN-25138

[2:2.0.3-2.giteb5fa88]

  • BR: systemd-devel
  • Related: RHELPLAN-25138

[2:2.0.3-1.giteb5fa88]

  • update to 2.0.3

[2:2.0.2-0.1.dev.git422ce21]

  • build latest upstream master

[2:2.0.0-2]

  • remove BR: go-md2man since no manpages yet

container-selinux [2:2.124.0-1]

  • update to 2.124.0
  • Related: RHELPLAN-25138

fuse-overlayfs [0.7.2-5]

  • be sure to work properly also with older rhel8 kernels, thanks to Giuseppe Scrivano
  • Resolves: #1803495

[0.7.2-4]

  • latest iteration of segfault fix patch, thanks to Giuseppe Scrivano
  • Resolves: #1803495

[0.7.2-3]

  • fix fuse-overlayfs segfault
  • Resolves: #1805016

[0.7.2-2]

  • fix useradd and groupadd fail under rootless Buildah and podman
  • Resolves: #1803495

podman [1.6.4-4.0.1]

[1.6.4-4]

  • fix podman (1.6.4) rhel 8.1 no route to host from inside container
  • Resolves: #1806900

[1.6.4-3]

  • fix Podman support for FIPS Mode requires a bind mount inside the container
  • Resolves: #1804194

python-podman-api [1.2.0-0.2.gitd0a45fe]

  • revert update to 1.6.0 due to new python3-pbr dependency which is not in RHEL
  • Related: RHELPLAN-25138

runc [1.0.0-64.rc9]

  • use no_openssl in BUILDTAGS (no vendored crypto in runc)
  • Related: RHELPLAN-25138

[1.0.0-63.rc9]

  • be sure to use golang >= 1.12.12-4
  • Related: RHELPLAN-25138

[1.0.0-62.rc9]

  • rebuild because of CVE-2019-9512 and CVE-2019-9514
  • Related: RHELPLAN-25138

[1.0.0-61.rc9]

  • update to runc 1.0.0-rc9 release
  • amend golang deps
  • fixes CVE-2019-16884

[1.0.0-60.rc8]

  • Resolves: #1721247 - enable fips mode

[1.0.0-59.rc8]

  • Resolves: #1720654 - rebase to v1.0.0-rc8

[1.0.0-57.rc5.dev.git2abd837]

  • Resolves: #1693424 - podman rootless: cannot specify gid= mount options

skopeo [0.1.40-8.0.1]

  • Add oracle registry into the conf file [Orabug: 29845934]
  • Fix oracle registry login issues [Orabug: 29937192]

[1:0.1.40-8]

  • change the search order of registries and remove quay.io (#1784267)

slirp4netns [0.4.2-3.git21fdece]

  • Fix CVE-2020-8608
  • Related: RHELPLAN-25138

toolbox [0.0.4-1.el8]

  • Update for rhel8.1 container-tools module

udica [0.2.1-2]

  • initial import to container-tools 8.2.0
  • Related: RHELPLAN-25139

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

Module container-tools:ol8 is enabled

buildah

1.11.6-6.0.1.module+el8.1.1+5573+1c3f6079

buildah-tests

1.11.6-6.0.1.module+el8.1.1+5573+1c3f6079

cockpit-podman

11-1.module+el8.1.1+5502+fbec5cc6

conmon

2.0.6-1.module+el8.1.1+5502+fbec5cc6

container-selinux

2.124.0-1.module+el8.1.1+5502+fbec5cc6

containernetworking-plugins

0.8.3-4.0.1.module+el8.1.1+5502+fbec5cc6

containers-common

0.1.40-8.0.1.module+el8.1.1+5502+fbec5cc6

fuse-overlayfs

0.7.2-5.module+el8.1.1+5573+1c3f6079

podman

1.6.4-4.0.1.module+el8.1.1+5573+1c3f6079

podman-docker

1.6.4-4.0.1.module+el8.1.1+5573+1c3f6079

podman-manpages

1.6.4-4.0.1.module+el8.1.1+5573+1c3f6079

podman-remote

1.6.4-4.0.1.module+el8.1.1+5573+1c3f6079

podman-tests

1.6.4-4.0.1.module+el8.1.1+5573+1c3f6079

python-podman-api

1.2.0-0.2.gitd0a45fe.module+el8.1.1+5502+fbec5cc6

runc

1.0.0-64.rc9.module+el8.1.1+5502+fbec5cc6

skopeo

0.1.40-8.0.1.module+el8.1.1+5502+fbec5cc6

skopeo-tests

0.1.40-8.0.1.module+el8.1.1+5502+fbec5cc6

slirp4netns

0.4.2-3.git21fdece.module+el8.1.1+5573+1c3f6079

toolbox

0.0.4-1.module+el8.1.1+5502+fbec5cc6

udica

0.2.1-2.module+el8.1.1+5502+fbec5cc6

Oracle Linux x86_64

Module container-tools:ol8 is enabled

buildah

1.11.6-6.0.1.module+el8.1.1+5573+1c3f6079

buildah-tests

1.11.6-6.0.1.module+el8.1.1+5573+1c3f6079

cockpit-podman

11-1.module+el8.1.1+5502+fbec5cc6

conmon

2.0.6-1.module+el8.1.1+5502+fbec5cc6

container-selinux

2.124.0-1.module+el8.1.1+5502+fbec5cc6

containernetworking-plugins

0.8.3-4.0.1.module+el8.1.1+5502+fbec5cc6

containers-common

0.1.40-8.0.1.module+el8.1.1+5502+fbec5cc6

fuse-overlayfs

0.7.2-5.module+el8.1.1+5573+1c3f6079

podman

1.6.4-4.0.1.module+el8.1.1+5573+1c3f6079

podman-docker

1.6.4-4.0.1.module+el8.1.1+5573+1c3f6079

podman-manpages

1.6.4-4.0.1.module+el8.1.1+5573+1c3f6079

podman-remote

1.6.4-4.0.1.module+el8.1.1+5573+1c3f6079

podman-tests

1.6.4-4.0.1.module+el8.1.1+5573+1c3f6079

python-podman-api

1.2.0-0.2.gitd0a45fe.module+el8.1.1+5502+fbec5cc6

runc

1.0.0-64.rc9.module+el8.1.1+5502+fbec5cc6

skopeo

0.1.40-8.0.1.module+el8.1.1+5502+fbec5cc6

skopeo-tests

0.1.40-8.0.1.module+el8.1.1+5502+fbec5cc6

slirp4netns

0.4.2-3.git21fdece.module+el8.1.1+5573+1c3f6079

toolbox

0.0.4-1.module+el8.1.1+5502+fbec5cc6

udica

0.2.1-2.module+el8.1.1+5502+fbec5cc6

Связанные CVE

Связанные уязвимости

CVSS3: 5.6
ubuntu
больше 5 лет назад

In libslirp 4.1.0, as used in QEMU 4.2.0, tcp_subr.c misuses snprintf return values, leading to a buffer overflow in later code.

CVSS3: 5.6
redhat
больше 5 лет назад

In libslirp 4.1.0, as used in QEMU 4.2.0, tcp_subr.c misuses snprintf return values, leading to a buffer overflow in later code.

CVSS3: 5.6
nvd
больше 5 лет назад

In libslirp 4.1.0, as used in QEMU 4.2.0, tcp_subr.c misuses snprintf return values, leading to a buffer overflow in later code.

CVSS3: 5.6
debian
больше 5 лет назад

In libslirp 4.1.0, as used in QEMU 4.2.0, tcp_subr.c misuses snprintf ...

suse-cvrf
почти 5 лет назад

Security update for xen

Уязвимость ELSA-2020-1379