Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2022-20240

Опубликовано: 22 авг. 2022
Источник: oracle-oval
Платформа: Oracle Linux 7

Описание

ELSA-2022-20240: podman security update (MODERATE)

[1.6.4-36.0.1]

  • Reduce unnecessary writable mounts in NaiveDiffDriver [Orabug: 31025483]
  • handle redirect from the docker registry v2 [Orabug: 29874238] (nikita.gerasimov@oracle.com)
  • remove changes in NaiveDiffDriver

[1.6.4-36]

[1.6.4-35]

[1.6.4-34]

  • fix RHEL7 regressions - thanks to Valentin Rothberg

[1.6.4-33]

Обновленные пакеты

Oracle Linux 7

Oracle Linux aarch64

podman

1.6.4-36.0.1.el7_9

podman-docker

1.6.4-36.0.1.el7_9

Oracle Linux x86_64

podman

1.6.4-36.0.1.el7_9

podman-docker

1.6.4-36.0.1.el7_9

Связанные CVE

Связанные уязвимости

CVSS3: 5.3
redhat
больше 3 лет назад

The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 advisory included an incorrect version of podman missing the fix for CVE-2020-14370, which was previously fixed via RHSA-2020:5056. This issue could possibly allow an attacker to gain access to sensitive information stored in environment variables.

CVSS3: 5.3
nvd
больше 3 лет назад

The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 advisory included an incorrect version of podman missing the fix for CVE-2020-14370, which was previously fixed via RHSA-2020:5056. This issue could possibly allow an attacker to gain access to sensitive information stored in environment variables.

CVSS3: 7.5
redhat
больше 3 лет назад

The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 advisory included an incorrect version of podman missing the fix for CVE-2020-8945, which was previously fixed via RHSA-2020:2117. This issue could possibly be used to crash or cause potential code execution in Go applications that use the Go GPGME wrapper library, under certain conditions, during GPG signature verification.

CVSS3: 7.5
nvd
больше 3 лет назад

The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 advisory included an incorrect version of podman missing the fix for CVE-2020-8945, which was previously fixed via RHSA-2020:2117. This issue could possibly be used to crash or cause potential code execution in Go applications that use the Go GPGME wrapper library, under certain conditions, during GPG signature verification.

CVSS3: 7.5
github
больше 3 лет назад

The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 advisory included an incorrect version of podman missing the fix for CVE-2020-14370, which was previously fixed via RHSA-2020:5056. This issue could possibly allow an attacker to gain access to sensitive information stored in environment variables.