Описание
Security update for virt-bootstrap
This update for virt-bootstrap fixes the following issues:
Security issue fixed:
- CVE-2019-13314: Allow providing the container's root password using a file (bsc#1140750).
This update was imported from the SUSE:SLE-15:Update update project.
Список пакетов
openSUSE Leap 15.1
python2-virt-bootstrap-1.0.0-lp151.4.3.1
python3-virt-bootstrap-1.0.0-lp151.4.3.1
Ссылки
- E-Mail link for openSUSE-SU-2020:1856-1
- SUSE Security Ratings
- SUSE Bug 1140750
- SUSE CVE CVE-2019-13314 page
Описание
virt-bootstrap 1.1.0 allows local users to discover a root password by listing a process, because this password may be present in the --root-password option to virt_bootstrap.py.
Затронутые продукты
openSUSE Leap 15.1:python2-virt-bootstrap-1.0.0-lp151.4.3.1
openSUSE Leap 15.1:python3-virt-bootstrap-1.0.0-lp151.4.3.1
Ссылки
- CVE-2019-13314
- SUSE Bug 1140750