Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2024-3827

Опубликовано: 11 июн. 2024
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2024-3827: buildah security and bug fix update (MODERATE)

[1.33.7-2.0.1]

  • Drop nmap-ncat requirement and skip ignore-socket test case [Orabug: 34117178]

[2:1.33.7-2]

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

buildah

1.33.7-2.0.1.el9_4

buildah-tests

1.33.7-2.0.1.el9_4

Oracle Linux x86_64

buildah

1.33.7-2.0.1.el9_4

buildah-tests

1.33.7-2.0.1.el9_4

Связанные уязвимости

rocky
около 1 года назад

Moderate: buildah security and bug fix update

rocky
около 1 года назад

Moderate: podman security and bug fix update

oracle-oval
около 1 года назад

ELSA-2024-3826: podman security and bug fix update (MODERATE)

oracle-oval
около 1 года назад

ELSA-2024-3968: container-tools:ol8 bug fix and enhancement update (MODERATE)

CVSS3: 6.5
ubuntu
больше 1 года назад

When parsing a multipart form (either explicitly with Request.ParseMultipartForm or implicitly with Request.FormValue, Request.PostFormValue, or Request.FormFile), limits on the total size of the parsed form were not applied to the memory consumed while reading a single form line. This permits a maliciously crafted input containing very long lines to cause allocation of arbitrarily large amounts of memory, potentially leading to memory exhaustion. With fix, the ParseMultipartForm function now correctly limits the maximum size of form lines.

Уязвимость ELSA-2024-3827