Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2022-7950

Опубликовано: 22 нояб. 2022
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2022-7950: Image Builder security, bug fix, and enhancement update (LOW)

cockpit-composer [41-1.0.1]

  • Make per page documentation links point to Oracle Linux [Orabug: 32013095], [Orabug:34398922]

[41-1]

  • New upstream release

[40-1]

  • New upstream release

[39-1]

  • New upstream release

[38-1]

  • New upstream release

[37-1]

  • New upstream release

[35-1]

  • New upstream release

[34-1]

  • New upstream release

[33-1]

  • Add support for OCI upload target
  • Update translations
  • Update dependencies

[32-1]

  • Add Edge Raw, RHEL Installer, Edge Simplified Installer image types
  • Improve user account modal responsiveness
  • Update tests
  • Update minor NPM dependencies
  • Update translation files

[31-1]

  • Add new ostree image types
  • Improve loading state when waiting for api responses
  • Improve notification system
  • Improve test stability
  • Update NPM dependencies
  • Update translations

[30-3]

  • Rebuilt for IMA sigs, glibc 2.34, aarch64 flags Related: rhbz#1991688

[30-2]

  • Rebuilt for RHEL 9 BETA on Apr 15th 2021. Related: rhbz#1947937

[30-1]

  • Add and update translations
  • Update NPM dependencies
  • Improve test reliability

[28-2]

[28-1]

  • Use sentence case rather than title case
  • Add and update tests
  • Update translations from weblate
  • Update minor NPM dependencies

[27-1]

  • Improve test reliability
  • Update translations from weblate
  • Update minor NPM dependencies

[26-1]

  • Add additional form validation for the Create Image Wizard
  • Improve page size dropdown styling
  • Update minor NPM dependencies
  • Improve code styling
  • Improve test reliability

osbuild [65-1]

  • New upstream release

[64-1]

  • New upstream release

[63-1]

  • New upstream release

[62-1]

  • New upstream release

[61-1]

  • New upstream release

[60-1]

  • New upstream release

[59-1]

  • New upstream release

[58-1]

  • New upstream release

[57-1]

  • New upstream release

[56-1]

  • New upstream release

[55-1]

  • New upstream release

[54-1]

  • New upstream release

[53-1]

  • New upstream release

[52-1]

  • New upstream release

[50-1]

  • New upstream release

[49-1]

  • New upstream release

[48-1]

  • New upstream release

[47-1]

  • New upstream release

[46-1]

  • New upstream release

[45-1]

  • New upstream release

[44-1]

  • New upstream release

[43-1]

  • New upstream release

[42-1]

  • New upstream release

[39-1]

  • New upstream release

[35-1]

  • Upstream release 35

[34-1]

  • Upstream release 34

[33-1]

  • Upstream release 33

[32-1]

  • Upstream release 32

[31-1]

  • Upstream release 31

[30-1]

  • Upstream release 30
  • Many new stages for building ostree-based raw images
  • Bootiso.mono stage was deprecated and split into smaller stages
  • Mounts are now represented as an array in a manifest
  • Various bug fixes and improvements to various stages

[29-2]

  • Rebuilt for IMA sigs, glibc 2.34, aarch64 flags Related: rhbz#1991688

[29-1]

  • Upstream release 29
  • Adds host services
  • Adds modprobe and logind stage

[27-3]

  • Rebuilt for RHEL 9 BETA on Apr 15th 2021. Related: rhbz#1947937

[27-2]

  • Include Fedora 35 runner (upstream commit 337e0f0)

[27-1]

  • Upstream release 27
  • Various bug fixes related to the new container and installer stages introdcued in version 25 and 26.

[26-1]

  • Upstream release 26
  • Support for building boot isos
  • Grub stage gained support for saved_entry to fix grub tooling

[25-1]

  • Upstream release 25
  • First tech preview of the new manifest format. Includes various new stages and inputs to be able to build ostree commits contained in a oci archive.

[24-1]

  • Upstream release 24
  • Turn on dependency generator for everything but runners
  • Include new input binaries

[23-2]

[23-1]

  • Upstream release 23
  • Do not mangle shebangs for assemblers, runners & stages.

[22-1]

  • Upstream release 22

[21-1]

  • Upstream reelase 21

osbuild-composer [62.1-1]

  • New upstream release

[62-1]

  • New upstream release

[60-1]

  • New upstream release

[59-1]

  • New upstream release

[58-1]

  • New upstream release

[57-1]

  • New upstream release

[55-1]

  • New upstream release

[54-1]

  • New upstream release

[53-1]

  • New upstream release

[51-1]

  • New upstream release

[46-1]

  • New upstream release

[45-1]

  • New upstream release

[44-1]

  • New upstream release

[43-1]

  • New upstream release

[42-1]

  • New upstream release

[41-1]

  • New upstream release

[40-1]

  • New upstream release

[39-1]

  • New upstream release

[38-1]

  • New upstream release
  • Tue Nov 02 2021 lavocatt - 37-1
  • New upstream release

[36-1]

  • New upstream release

[33-1]

  • New upstream release

[32-1]

  • New upstream release

[31-1]

  • New upstream release

[30-2]

  • Rebuilt for IMA sigs, glibc 2.34, aarch64 flags Related: rhbz#1991688

[30-1]

  • New upstream release

[29-3]

  • Rebuilt for RHEL 9 BETA for openssl 3.0 Related: rhbz#1971065

[29-2]

  • Rebuilt for RHEL 9 BETA on Apr 15th 2021. Related: rhbz#1947937

[29-1]

  • New upstream release

[28-1]

  • New upstream release

[27-1]

  • New upstream release

[26-3]

[26-2]

  • Fix the compatibility with a new golang-github-azure-storage-blob 0.12

[26-1]

  • New upstream release

[25-1]

  • New upstream release

[24-1]

  • New upstream release

[23-1]

  • New upstream release

[22-1]

  • New upstream release

weldr-client [35.5-4]

  • tests: Add osbuild-composer repo file for RHEL 9.1 Related: rhbz#2118831

[35.5-3]

  • tests: Update tests for osbuild composer changes Resolves: rhbz#2118831

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

cockpit-composer

41-1.0.1.el9

osbuild

65-1.el9

osbuild-composer

62.1-1.el9

osbuild-composer-core

62.1-1.el9

osbuild-composer-dnf-json

62.1-1.el9

osbuild-composer-worker

62.1-1.el9

osbuild-luks2

65-1.el9

osbuild-lvm2

65-1.el9

osbuild-ostree

65-1.el9

osbuild-selinux

65-1.el9

python3-osbuild

65-1.el9

weldr-client

35.5-4.el9

Oracle Linux x86_64

cockpit-composer

41-1.0.1.el9

osbuild

65-1.el9

osbuild-composer

62.1-1.el9

osbuild-composer-core

62.1-1.el9

osbuild-composer-dnf-json

62.1-1.el9

osbuild-composer-worker

62.1-1.el9

osbuild-luks2

65-1.el9

osbuild-lvm2

65-1.el9

osbuild-ostree

65-1.el9

osbuild-selinux

65-1.el9

python3-osbuild

65-1.el9

weldr-client

35.5-4.el9

Связанные CVE

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 3 года назад

A too-short encoded message can cause a panic in Float.GobDecode and Rat GobDecode in math/big in Go before 1.17.13 and 1.18.5, potentially allowing a denial of service.

CVSS3: 6.5
redhat
почти 3 года назад

A too-short encoded message can cause a panic in Float.GobDecode and Rat GobDecode in math/big in Go before 1.17.13 and 1.18.5, potentially allowing a denial of service.

CVSS3: 7.5
nvd
почти 3 года назад

A too-short encoded message can cause a panic in Float.GobDecode and Rat GobDecode in math/big in Go before 1.17.13 and 1.18.5, potentially allowing a denial of service.

CVSS3: 7.5
msrc
почти 3 года назад

Описание отсутствует

CVSS3: 7.5
debian
почти 3 года назад

A too-short encoded message can cause a panic in Float.GobDecode and R ...

Уязвимость ELSA-2022-7950