Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2024:9135

Опубликовано: 17 мар. 2025
Источник: rocky
Оценка: Moderate

Описание

Moderate: toolbox security update

Toolbox is a tool for Linux operating systems, which allows the use of containerized command line environments. It is built on top of Podman and other standard container technologies from OCI.

Security Fix(es):

  • golang: net/http: golang: mime/multipart: golang: net/textproto: memory exhaustion in Request.ParseMultipartForm (CVE-2023-45290)

  • golang: html/template: errors returned from MarshalJSON methods may break template escaping (CVE-2024-24785)

  • golang: net: malformed DNS message can cause infinite loop (CVE-2024-24788)

  • net/http: Denial of service due to improper 100-continue handling in net/http (CVE-2024-24791)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Rocky Linux 9.5 Release Notes linked from the References section.

Затронутые продукты

  • Rocky Linux 9

НаименованиеАрхитектураРелизRPM
toolboxx86_645.el9.rocky.0.2toolbox-0.0.99.5-5.el9.rocky.0.2.x86_64.rpm
toolbox-testsx86_645.el9.rocky.0.2toolbox-tests-0.0.99.5-5.el9.rocky.0.2.x86_64.rpm

Показывать по

Связанные уязвимости

suse-cvrf
12 месяцев назад

Security update for go1.22-openssl

suse-cvrf
12 месяцев назад

Security update for go1.22-openssl

oracle-oval
около 1 года назад

ELSA-2024-6969: container-tools:ol8 security update (MODERATE)

suse-cvrf
12 месяцев назад

Security update for go1.21-openssl

suse-cvrf
около 1 года назад

Security update for go1.21-openssl