Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2020-5823

Опубликовано: 24 авг. 2020
Источник: oracle-oval
Платформа: Oracle Linux 7

Описание

ELSA-2020-5823: docker-cli docker-engine security update (IMPORTANT)

docker-cli [19.03.11-5]

  • Bugfix for 'docker images [name]' not working on docker 19.03.11-ol
  • Address CVE-2020-16845

[19.03.11-4]

  • added patch for registry list

[19.03.11-3]

  • update to 19.03.11 for CVE-2020-13401

[19.03.1-1.0.0]

  • update to 19.03.1

[19.03-0.0.1]

  • update to 19.03

[18.09.1-1.0.6]

  • disable kmem accounting for UEKR4

[18.09.1-1.0.5]

  • apply e4931e664feac6fa8846f3f04268a0cc98822549, fixes CVE-2019-5736

[18.09.1-1.0.4]

  • fix authentication error when using docker hub and using --default-registry

[18.09.1-1.0.3]

  • fix authentication errors when using docker hub

[18.09-1.0.0]

  • rename to docker-cli

[18.09-0.0.1]

  • merge docker-engine.spec changes by Oracle into docker-ce-cli.spec from upstream 18.09 branch

docker-engine [19.03.11-5]

  • Bugfix for 'docker images [name]' not working on docker 19.03.11-ol
  • Address CVE-2020-16845

[19.03.11-4]

  • added patch for registry list

[19.03.11-3]

  • update to 19.03.11 for CVE-2020-13401

[19.03.1-1.0.0]

  • update to 19.03.1

[19.03-0.0.1]

  • update to 19.03

[18.09.1-1.0.6]

  • disable kmem accounting for UEKR4

[18.09.1-1.0.5]

  • apply e4931e664feac6fa8846f3f04268a0cc98822549, fixes CVE-2019-5736

[18.09.1-1.0.4]

  • fix authentication error when using docker hub and using --default-registry

[18.09.1-1.0.3]

  • fix authentication errors when using docker hub

[18.09.1-1.0.2]

  • use epoch in container-selinux dependency

[18.09.1-1.0.1]

  • fix 'docker cp doesn't work for btrfs' (OLM-158)
  • update build to Go 1.10.8

[18.09.1-1.0.0]

  • update to 18.09.1

[18.09-1.0.0]

  • rename back to docker-engine, rename dockerd-ce to dockerd and stop using alternatives

[18.09-0.0.1]

  • merge docker-engine.spec changes by Oracle into docker-ce.spec from upstream 18.09 branch

[18.03.1.ol-0.0.7]

  • fix [orabug 28452214] and [orabug 28461404]

[18.03.1.ol-0.0.6]

  • obsolete/provide the docker package [orabug 28216396]
  • Fix docker plugin reference resolution [orabug 28376247]

[18.03.1.ol-1.0.4]

  • Fixed issue where RPM overwrites config files

[17.12.0.ol-1.0.1]

  • Update docker-engine package for upstream 17.12.0

[17.09.1.ol-1.0.2]

  • Update docker-engine package for upstream 17.09.1

[17.06.2.ol-1.0.1]

  • Update docker-engine package for upstream 17.06.2 [orabug 26673768]
  • Migrate to new 'ol'-based versioning
  • add docker-storage-config utility

[17.03.1-ce-3.0.1]

  • Update docker-engine package for upstream 17.03.1
  • Enable configuration of Docker daemon via sysconfig [orabug 21804877]
  • Require UEK4 for docker 1.9 [orabug 22235639 22235645]
  • Add docker.conf for prelink [orabug 25147708]
  • Update oracle linux selinux policy to match upstream [orabug 25653794]
  • Use dockerd instead of docker daemon as it is deprecated [orabug 25653794]

Обновленные пакеты

Oracle Linux 7

Oracle Linux aarch64

docker-cli

19.03.11.ol-5.el7

docker-engine

19.03.11.ol-5.el7

Oracle Linux x86_64

docker-cli

19.03.11.ol-5.el7

docker-engine

19.03.11.ol-5.el7

Связанные CVE

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 5 лет назад

Go before 1.13.15 and 14.x before 1.14.7 can have an infinite read loop in ReadUvarint and ReadVarint in encoding/binary via invalid inputs.

CVSS3: 7.5
redhat
почти 5 лет назад

Go before 1.13.15 and 14.x before 1.14.7 can have an infinite read loop in ReadUvarint and ReadVarint in encoding/binary via invalid inputs.

CVSS3: 7.5
nvd
почти 5 лет назад

Go before 1.13.15 and 14.x before 1.14.7 can have an infinite read loop in ReadUvarint and ReadVarint in encoding/binary via invalid inputs.

CVSS3: 7.5
msrc
почти 5 лет назад

Описание отсутствует

CVSS3: 7.5
debian
почти 5 лет назад

Go before 1.13.15 and 14.x before 1.14.7 can have an infinite read loo ...

Уязвимость ELSA-2020-5823