Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2021-0531

Опубликовано: 20 фев. 2021
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2021-0531: container-tools:ol8 security, bug fix, and enhancement update (MODERATE)

buildah [1.16.7-4.0.1]

  • Handling redirect from the docker registry [Orabug: 29874238] (Nikita Gerasimov)

[1.16.7-4]

[1.16.7-3]

  • revert back to buildah-1.16 for the quarterly release
  • Related: #1888571

[1.19.0-2]

  • bump version to refrect buildah upgrade
  • Related: #1888571

[1.16.7-2]

  • bump to release-1.19 branch
  • Related: #1888571

[1.16.5-5]

[1.16.5-4]

  • simplify spec file
  • use short commit ID in tarball name
  • Related: #1888571

[1.16.5-3]

[1.16.5-2]

  • use shortcommit ID in branch tarball name
  • Related: #1888571

[1.16.5-1]

  • synchronize with stream-container-tools-rhel8-rhel-8.4.0
  • Related: #1888571

cockpit-podman [27.1-3]

  • run much more tests - patch from Matej Marusak
  • Related: #1888571

[27.1-2]

  • gating tests - always set VM password
  • Related: #1888571

[27.1-1]

[27-1]

[26-1]

[25-5]

  • remove redundant patch
  • Related: #1888571

[25-4]

  • replace docker.io with quay.io for gating tests due do docker.io new pull rate limit requirements
  • Related: #1888571

[25-3]

  • test: Cleanup images before pulling the ones we need - thanks to Matej Marusak
  • Related: #1888571

[25-2]

  • remove hack in tests
  • add LICENSE
  • Related: #1888571

[25-1]

  • synchronize with stream-container-tools-rhel8-rhel-8.4.0
  • Related: #1888571

conmon [2:2.0.22-3]

  • exclude i686 as golang is not suppoerted there
  • Related: #1888571

[2:2.0.22-2]

  • add BR: golang, go-md2man
  • add man pages
  • Related: #1888571

[2:2.0.22-1]

[2:2.0.21-3]

  • simplify spec
  • Related: #1888571

[2:2.0.21-2]

  • be sure to harden the linked binary
  • compile with debuginfo enabled
  • Related: #1888571

[2:2.0.21-1]

  • synchronize with stream-container-tools-rhel8-rhel-8.4.0
  • Related: #1888571

containernetworking-plugins [0.9.0-1]

container-selinux [2:2.155.0-1]

[2:2.154.0-1]

[2:2.153.0-1]

[2:2.152.0-1]

[2:2.151.0-1]

[2:2.150.0-1]

[2:2.145.0-1]

  • synchronize with stream-container-tools-rhel8-rhel-8.4.0
  • Resolves: #1873064

criu [3.15-1]

[3.14-2]

  • fix 'Need to fix bugs found by coverity.'
  • Related: #1821193

[3.14-1]

  • synchronize containter-tools 8.3.0 with 8.2.1
  • Related: #1821193

crun [0.16-2]

  • exclude i686 because of build failures
  • Related: #1888571

[0.16-1]

[0.15.1-1]

[0.15-2]

[0.15-1]

  • synchronize with stream-container-tools-rhel8-rhel-8.4.0
  • Related: #1888571

fuse-overlayfs [1.3.0-2]

  • disable openat2 syscall again - still unsupported in current RHEL8 kernel
  • Resolves: #1921863

[1.3.0-1]

[1.2.0-3]

  • be sure to harden the linked binary
  • Related: #1888571

[1.2.0-2]

  • ensure fuse module is loaded
  • Related: #1888571

[1.2.0-1]

  • synchronize with stream-container-tools-rhel8-rhel-8.4.0
  • Related: #1888571

libslirp oci-seccomp-bpf-hook [1.2.0-1]

podman [2.2.1-7.0.1]

  • Handling redirect from the docker registry [Orabug: 29874238] (Nikita Gerasimov)

[2.2.1-7]

[2.2.1-6]

[2.2.1-5]

[2.2.1-4]

  • add Requires: oci-runtime
  • Related: #1888571

[2.2.1-3]

[2.2.1-2]

[2.2.1-1]

[2.2.0-2]

  • attempt to fix gatng tests
  • Related: #1888571

[2.2.0-1]

[2.1.1-3]

  • attempt to fix linker error with golang-1.15
  • add Requires: httpd-tools to tests, needed to work around missing htpasswd in docker registry image, thanks to Ed Santiago
  • Related: #1888571

[2.1.1-2]

[2.1.1-1]

  • update podman to 2.1.1-rhel
  • Resolves: #1743687
  • Resolves: #1811570
  • Resolves: #1869322
  • Resolves: #1678546
  • Resolves: #1853455
  • Resolves: #1874271

python-podman-api [1.2.0-0.2.gitd0a45fe]

  • revert update to 1.6.0 due to new python3-pbr dependency which is not in RHEL
  • Related: RHELPLAN-25139

[1.2.0-0.1.gitd0a45fe]

  • Initial package

runc [1.0.0-70.rc92]

  • add Provides: oci-runtime = 1
  • Related: #1888571

[1.0.0-69.rc92]

  • still use ExcludeArch as go_arches macro is broken for 8.4
  • Related: #1888571

skopeo [1:1.2.0-9.0.1]

  • Handling redirect from the docker registry [Orabug: 29874238] (Nikita Gerasimov)
  • Add oracle registry into the conf file [Orabug: 29845934 31306708]

[1:1.2.0-9]

  • upload proper source tarball
  • Related: #1888571

[1:1.2.0-8]

  • revert back to version aimed at 8.3.1 - skopeo-1.2.0
  • also downgrade versions of vendored libraries
  • Related: #1888571

[1:1.2.1-1]

[1:1.2.0-6]

  • always build with debuginfo
  • use less verbose output when compiling
  • Related: #1888571

[1:1.2.0-5]

  • re-sync config files
  • assure events_logger = 'file'
  • Related: #1888571

[1:1.2.0-4]

  • change default logging mechanism to use for container engine events in containers.conf to be events_logger = 'file' - it should fix RHEL gating tests for podman nonroot (thanks to Dan Walsh)
  • Related: #1888571

[1:1.2.0-3]

  • simplify spec file
  • use short commit ID in tarball name
  • Related: #1888571

[1:1.2.0-2]

  • use shortcommit ID in branch tarball name
  • Related: #1888571

[1:1.2.0-1]

  • synchronize with stream-container-tools-rhel8-rhel-8.4.0
  • Related: #1888571

slirp4netns [1.1.8-1]

[1.1.7-2]

  • exclude i686 because of build failures
  • Related: #1888571

[1.1.7-1]

[1.1.6-2]

    • be sure to harden the linked binary
  • Related: #1888571

[1.1.6-1]

udica [0.2.4-1]

[0.2.3-1]

  • synchronize with stream-container-tools-rhel8-rhel-8.4.0
  • Related: #1888571

[0.2.2-1]

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

Module container-tools:ol8 is enabled

buildah

1.16.7-4.0.1.module+el8.3.1+9659+c1901784

buildah-tests

1.16.7-4.0.1.module+el8.3.1+9659+c1901784

cockpit-podman

27.1-3.module+el8.3.1+9659+c1901784

conmon

2.0.22-3.module+el8.3.1+9659+c1901784

container-selinux

2.155.0-1.module+el8.3.1+9659+c1901784

containernetworking-plugins

0.9.0-1.module+el8.3.1+9659+c1901784

containers-common

1.2.0-9.0.1.module+el8.3.1+9659+c1901784

crit

3.15-1.module+el8.3.1+9659+c1901784

criu

3.15-1.module+el8.3.1+9659+c1901784

crun

0.16-2.module+el8.3.1+9659+c1901784

fuse-overlayfs

1.3.0-2.module+el8.3.1+9659+c1901784

libslirp

4.3.1-1.module+el8.3.1+9659+c1901784

libslirp-devel

4.3.1-1.module+el8.3.1+9659+c1901784

oci-seccomp-bpf-hook

1.2.0-1.module+el8.3.1+9659+c1901784

podman

2.2.1-7.0.1.module+el8.3.1+9659+c1901784

podman-catatonit

2.2.1-7.0.1.module+el8.3.1+9659+c1901784

podman-docker

2.2.1-7.0.1.module+el8.3.1+9659+c1901784

podman-plugins

2.2.1-7.0.1.module+el8.3.1+9659+c1901784

podman-remote

2.2.1-7.0.1.module+el8.3.1+9659+c1901784

podman-tests

2.2.1-7.0.1.module+el8.3.1+9659+c1901784

python-podman-api

1.2.0-0.2.gitd0a45fe.module+el8.3.1+9659+c1901784

python3-criu

3.15-1.module+el8.3.1+9659+c1901784

runc

1.0.0-70.rc92.module+el8.3.1+9659+c1901784

skopeo

1.2.0-9.0.1.module+el8.3.1+9659+c1901784

skopeo-tests

1.2.0-9.0.1.module+el8.3.1+9659+c1901784

slirp4netns

1.1.8-1.module+el8.3.1+9659+c1901784

udica

0.2.4-1.module+el8.3.1+9659+c1901784

Oracle Linux x86_64

Module container-tools:ol8 is enabled

buildah

1.16.7-4.0.1.module+el8.3.1+9659+c1901784

buildah-tests

1.16.7-4.0.1.module+el8.3.1+9659+c1901784

cockpit-podman

27.1-3.module+el8.3.1+9659+c1901784

conmon

2.0.22-3.module+el8.3.1+9659+c1901784

container-selinux

2.155.0-1.module+el8.3.1+9659+c1901784

containernetworking-plugins

0.9.0-1.module+el8.3.1+9659+c1901784

containers-common

1.2.0-9.0.1.module+el8.3.1+9659+c1901784

crit

3.15-1.module+el8.3.1+9659+c1901784

criu

3.15-1.module+el8.3.1+9659+c1901784

crun

0.16-2.module+el8.3.1+9659+c1901784

fuse-overlayfs

1.3.0-2.module+el8.3.1+9659+c1901784

libslirp

4.3.1-1.module+el8.3.1+9659+c1901784

libslirp-devel

4.3.1-1.module+el8.3.1+9659+c1901784

oci-seccomp-bpf-hook

1.2.0-1.module+el8.3.1+9659+c1901784

podman

2.2.1-7.0.1.module+el8.3.1+9659+c1901784

podman-catatonit

2.2.1-7.0.1.module+el8.3.1+9659+c1901784

podman-docker

2.2.1-7.0.1.module+el8.3.1+9659+c1901784

podman-plugins

2.2.1-7.0.1.module+el8.3.1+9659+c1901784

podman-remote

2.2.1-7.0.1.module+el8.3.1+9659+c1901784

podman-tests

2.2.1-7.0.1.module+el8.3.1+9659+c1901784

python-podman-api

1.2.0-0.2.gitd0a45fe.module+el8.3.1+9659+c1901784

python3-criu

3.15-1.module+el8.3.1+9659+c1901784

runc

1.0.0-70.rc92.module+el8.3.1+9659+c1901784

skopeo

1.2.0-9.0.1.module+el8.3.1+9659+c1901784

skopeo-tests

1.2.0-9.0.1.module+el8.3.1+9659+c1901784

slirp4netns

1.1.8-1.module+el8.3.1+9659+c1901784

udica

0.2.4-1.module+el8.3.1+9659+c1901784

Связанные CVE

Связанные уязвимости

CVSS3: 5.3
ubuntu
почти 5 лет назад

An information disclosure vulnerability was found in containers/podman in versions before 2.0.5. When using the deprecated Varlink API or the Docker-compatible REST API, if multiple containers are created in a short duration, the environment variables from the first container will get leaked into subsequent containers. An attacker who has control over the subsequent containers could use this flaw to gain access to sensitive information stored in such variables.

CVSS3: 5.3
redhat
почти 5 лет назад

An information disclosure vulnerability was found in containers/podman in versions before 2.0.5. When using the deprecated Varlink API or the Docker-compatible REST API, if multiple containers are created in a short duration, the environment variables from the first container will get leaked into subsequent containers. An attacker who has control over the subsequent containers could use this flaw to gain access to sensitive information stored in such variables.

CVSS3: 5.3
nvd
почти 5 лет назад

An information disclosure vulnerability was found in containers/podman in versions before 2.0.5. When using the deprecated Varlink API or the Docker-compatible REST API, if multiple containers are created in a short duration, the environment variables from the first container will get leaked into subsequent containers. An attacker who has control over the subsequent containers could use this flaw to gain access to sensitive information stored in such variables.

CVSS3: 5.3
debian
почти 5 лет назад

An information disclosure vulnerability was found in containers/podman ...

suse-cvrf
больше 4 лет назад

Security update for podman