Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2024-8563

Опубликовано: 29 окт. 2024
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2024-8563: buildah security update (IMPORTANT)

[1.33.10-1.0.1]

  • Drop nmap-ncat requirement and skip ignore-socket test case [Orabug: 34117178]

[2:1.33.10-1]

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

buildah

1.33.10-1.0.1.el9_4

buildah-tests

1.33.10-1.0.1.el9_4

Oracle Linux x86_64

buildah

1.33.10-1.0.1.el9_4

buildah-tests

1.33.10-1.0.1.el9_4

Связанные CVE

Связанные уязвимости

CVSS3: 7.8
ubuntu
8 месяцев назад

A vulnerability was found in Buildah. Cache mounts do not properly validate that user-specified paths for the cache are within our cache directory, allowing a `RUN` instruction in a Container file to mount an arbitrary directory from the host (read/write) into the container as long as those files can be accessed by the user running Buildah.

CVSS3: 7.8
redhat
8 месяцев назад

A vulnerability was found in Buildah. Cache mounts do not properly validate that user-specified paths for the cache are within our cache directory, allowing a `RUN` instruction in a Container file to mount an arbitrary directory from the host (read/write) into the container as long as those files can be accessed by the user running Buildah.

CVSS3: 7.8
nvd
8 месяцев назад

A vulnerability was found in Buildah. Cache mounts do not properly validate that user-specified paths for the cache are within our cache directory, allowing a `RUN` instruction in a Container file to mount an arbitrary directory from the host (read/write) into the container as long as those files can be accessed by the user running Buildah.

CVSS3: 7.8
debian
8 месяцев назад

A vulnerability was found in Buildah. Cache mounts do not properly val ...

suse-cvrf
8 месяцев назад

Security update for buildah