Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2020:1926

Опубликовано: 28 апр. 2020
Источник: rocky
Оценка: Important

Описание

Important: container-tools:1.0 security and bug fix update

The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.

Security Fix(es):

  • buildah: Crafted input tar file may lead to local file overwrite during image build process (CVE-2020-10696)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Bug Fix(es):

  • conflicting requests: failed to install container-tools:1.0 (BZ#1813776)

  • podman run container error with avc denied (BZ#1816541)

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
container-selinuxnoarch1.gitf958d0c.module+el8.5.0+681+c9a1951fcontainer-selinux-2.124.0-1.gitf958d0c.module+el8.5.0+681+c9a1951f.noarch.rpm
critx86_649.module+el8.5.0+681+c9a1951fcrit-3.12-9.module+el8.5.0+681+c9a1951f.x86_64.rpm
criux86_649.module+el8.5.0+681+c9a1951fcriu-3.12-9.module+el8.5.0+681+c9a1951f.x86_64.rpm
fuse-overlayfsx86_645.module+el8.5.0+681+c9a1951ffuse-overlayfs-0.3-5.module+el8.5.0+681+c9a1951f.x86_64.rpm
oci-systemd-hookx86_642.git2d0b8a3.module+el8.4.0+557+48ba8b2foci-systemd-hook-0.1.15-2.git2d0b8a3.module+el8.4.0+557+48ba8b2f.x86_64.rpm
oci-umountx86_642.git87f9237.module+el8.4.0+557+48ba8b2foci-umount-2.3.4-2.git87f9237.module+el8.4.0+557+48ba8b2f.x86_64.rpm
python3-criux86_649.module+el8.5.0+681+c9a1951fpython3-criu-3.12-9.module+el8.5.0+681+c9a1951f.x86_64.rpm
runcx86_6456.rc5.dev.git2abd837.module+el8.5.0+681+c9a1951frunc-1.0.0-56.rc5.dev.git2abd837.module+el8.5.0+681+c9a1951f.x86_64.rpm
slirp4netnsx86_645.dev.gitc4e1bc5.module+el8.5.0+681+c9a1951fslirp4netns-0.1-5.dev.gitc4e1bc5.module+el8.5.0+681+c9a1951f.x86_64.rpm

Показывать по

Связанные CVE

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 5 лет назад

A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker to trick a user into building a malicious container image hosted on an HTTP(s) server and then write files to the user's system anywhere that the user has permissions.

CVSS3: 8.8
redhat
около 5 лет назад

A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker to trick a user into building a malicious container image hosted on an HTTP(s) server and then write files to the user's system anywhere that the user has permissions.

CVSS3: 8.8
nvd
около 5 лет назад

A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker to trick a user into building a malicious container image hosted on an HTTP(s) server and then write files to the user's system anywhere that the user has permissions.

CVSS3: 8.8
debian
около 5 лет назад

A path traversal flaw was found in Buildah in versions before 1.14.5. ...

rocky
около 5 лет назад

Important: container-tools:rhel8 security update