Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2023-2283

Опубликовано: 15 мая 2023
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2023-2283: skopeo security and bug fix update (MODERATE)

[2:1.11.2-0.1]

[2:1.11.1-1]

[2:1.11.0-1]

  • update to 1.11.0 release
  • Related: #2124478

[2:1.11.0-0.4]

[2:1.11.0-0.3]

[2:1.11.0-0.2]

[2:1.11.0-0.1]

[2:1.10.0-1]

[2:1.9.3-1]

[2:1.9.2-1]

[2:1.9.1-1]

[2:1.9.0-1]

[2:1.8.0-4]

  • Re-enable debuginfo
  • Related: #2061316

[2:1.8.0-3]

  • BuildRequires: /usr/bin/go-md2man
  • Related: #2061316

[2:1.8.0-2]

  • enable LTO
  • Related: #1988128

[2:1.8.0-1]

[2:1.7.0-1]

[2:1.6.1-4]

  • add tags: classic (Ed Santiago)
  • Related: #2061316

[2:1.6.1-3]

  • remove BATS from required packages (Ed Santiago)
  • Related: #2061316

[2:1.6.1-2]

  • be sure to install BATS before gating tests are executed (thanks to Ed Santiago)
  • Related: #2061316

[2:1.6.1-1]

[2:1.6.0-1]

[2:1.5.2-1]

[2:1.5.1-1]

[2:1.5.1-0.9]

[2:1.5.1-0.8]

[2:1.5.1-0.7]

[2:1.5.1-0.6]

[2:1.5.1-0.5]

[2:1.5.1-0.4]

  • bump Epoch to preserve upgrade patch from RHEL8
  • Related: #2000051

[1:1.5.1-0.3]

[1:1.5.1-0.2]

[1:1.5.1-0.1]

[1:1.4.1-0.14]

[1:1.4.1-0.13]

[1:1.4.1-0.12]

  • add skopeo tests from Fedora
  • Related: #2000051

[1:1.4.1-0.11]

[1:1.4.1-0.10]

  • add gating.yaml
  • Related: #2000051

[1:1.4.1-0.9]

[1:1.4.1-0.8]

[1:1.4.1-0.7]

[1:1.4.1-0.6]

[1:1.4.1-0.5]

[1:1.4.1-0.4]

[1:1.4.1-0.3]

[1:1.4.1-0.2]

[1:1.4.1-0.1]

[1:1.4.1-1]

  • rebuild with containers-common dep fixed
  • Related: #2000051

[1:1.4.0-7]

  • Rebuilt for IMA sigs, glibc 2.34, aarch64 flags Related: rhbz#1991688

[1:1.4.0-6]

  • be sure short-name-mode is permissive in RHEL8
  • Related: #1970747

[1:1.4.0-5]

  • don't define short-name-mode in RHEL8
  • Related: #1970747

[1:1.4.0-4]

  • put both RHEL8 and RHEL9 conditional configurations into update.sh
  • Related: #1970747

[1:1.4.0-3]

  • update vendored components
  • always require runc on RHEL8 or lesser
  • Related: #1970747

[1:1.4.0-2]

[1:1.4.0-1]

  • update to 1.4.0 release and switch to the release-1.4 maint branch
  • Related: #1970747

[1:1.4.0-0.2]

  • update vendored components
  • ship /etc/pki/rpm-gpg/RPM-GPG-KEY-redhat-release only on non-RHEL and CentOS distros
  • Related: #1970747

[1:1.4.0-0.1]

  • switch to the main branch of skopeo
  • Related: #1970747

[1:1.3.1-9]

  • Add support for signed RHEL images, enabled by default
  • Related: #1970747

[1:1.3.1-8]

  • update seccomp.json from Fedora to allow clone3 to pass
  • Related: #1970747

[1:1.3.1-7]

  • update shortnames from Pyxis
  • put RHEL9/UBI9 images into overrides
  • Related: #1970747

[1:1.3.1-6]

  • correct name of the option is 'short-name-mode' not 'short-names-mode'
  • Related: #1970747

[1:1.3.1-5]

  • handle CentOS Stream while updating vendored components
  • Related: #1970747

[1:1.3.1-4]

[1:1.3.1-3]

  • update registries.conf to be consistent with upstream
  • Related: #1970747

[1:1.3.1-2]

  • consume content from the release-1.3 upstream branch
  • Related: #1970747

[1:1.3.1-1]

[1:1.3.0-7]

  • Rebuilt for RHEL 9 BETA for openssl 3.0 Related: rhbz#1971065

[1:1.3.0-6]

  • set short-names-mode = 'enforcing' in registries.conf
  • Resolves: #1971752

[1:1.3.0-5]

  • configure for RHEL9
  • Related: #1970747

[1:1.3.0-4]

  • add missing containers-mounts.conf.5.md file to git
  • don't list/install the same doc twice
  • Related: #1970747

[1:1.3.0-3]

  • update to new versions of vendored components
  • fail is there is an issue in communication with Pyxis API
  • understand devel branch in update.sh script, use pkg wrapper
  • sync with Pyxis
  • use containers-mounts.conf.5.md from containers/common
  • Related: #1970747

[1:1.2.2-4]

  • Rebuilt for RHEL 9 BETA on Apr 15th 2021. Related: rhbz#1947937

[1:1.2.2-3]

  • disable LTO again

[1:1.2.2-2]

  • use rhel-shortnames only from trusted registries
  • sync with config files from current versions of vendored projects

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

skopeo

1.11.2-0.1.el9

skopeo-tests

1.11.2-0.1.el9

Oracle Linux x86_64

skopeo

1.11.2-0.1.el9

skopeo-tests

1.11.2-0.1.el9

Связанные CVE

Связанные уязвимости

CVSS3: 5.3
redos
около 1 года назад

Множественные уязвимости skopeo

oracle-oval
около 2 лет назад

ELSA-2023-2367: containernetworking-plugins security and bug fix update (MODERATE)

oracle-oval
около 2 лет назад

ELSA-2023-2282: podman security and bug fix update (MODERATE)

oracle-oval
около 2 лет назад

ELSA-2023-2253: buildah security and bug fix update (MODERATE)

oracle-oval
около 2 лет назад

ELSA-2023-2758: container-tools:ol8 security, bug fix, and enhancement update (MODERATE)

Уязвимость ELSA-2023-2283