Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2024-6194

Опубликовано: 03 сент. 2024
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2024-6194: podman security update (IMPORTANT)

[4.9.4-10.0.1]

  • Fixes issue of podman execvp error while using podmansh [Orabug: 36073625]
  • Improved saving remote build context to tarfile in Podman daemon [Orabug: 36495655]
  • Add devices on container startup, not on creation
  • Backport fast gzip for compression [Orabug: 36420418]
  • overlay: Put should ignore ENINVAL for Unmount [Orabug: 36234694]
  • Drop nmap-ncat requirement and skip ignore-socket test case [Orabug: 34117404]

[4:4.9.4-10]

[4:4.9.4-9]

[4:4.9.4-8]

[4:4.9.4-7]

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

podman

4.9.4-10.0.1.el9_4

podman-docker

4.9.4-10.0.1.el9_4

podman-plugins

4.9.4-10.0.1.el9_4

podman-remote

4.9.4-10.0.1.el9_4

podman-tests

4.9.4-10.0.1.el9_4

Oracle Linux x86_64

podman

4.9.4-10.0.1.el9_4

podman-docker

4.9.4-10.0.1.el9_4

podman-plugins

4.9.4-10.0.1.el9_4

podman-remote

4.9.4-10.0.1.el9_4

podman-tests

4.9.4-10.0.1.el9_4

Связанные уязвимости

oracle-oval
11 месяцев назад

ELSA-2024-5258: container-tools:ol8 security update (IMPORTANT)

CVSS3: 6
ubuntu
около 1 года назад

go-retryablehttp prior to 0.7.7 did not sanitize urls when writing them to its log file. This could lead to go-retryablehttp writing sensitive HTTP basic auth credentials to its log file. This vulnerability, CVE-2024-6104, was fixed in go-retryablehttp 0.7.7.

CVSS3: 6
redhat
около 1 года назад

go-retryablehttp prior to 0.7.7 did not sanitize urls when writing them to its log file. This could lead to go-retryablehttp writing sensitive HTTP basic auth credentials to its log file. This vulnerability, CVE-2024-6104, was fixed in go-retryablehttp 0.7.7.

CVSS3: 6
nvd
около 1 года назад

go-retryablehttp prior to 0.7.7 did not sanitize urls when writing them to its log file. This could lead to go-retryablehttp writing sensitive HTTP basic auth credentials to its log file. This vulnerability, CVE-2024-6104, was fixed in go-retryablehttp 0.7.7.

CVSS3: 5.5
msrc
10 месяцев назад

Описание отсутствует