RHSA-2019:3494-01 -- Redhat buildah, container-selinux, containernetworking-plugins, fuse-overlayfs, oci-systemd-hook, oci-umount, podman, runc, skopeo, slirp4netnsID: oval:org.secpod.oval:def:503434 | Date: (C)2019-10-28 (M)2022-04-05 |
Class: PATCH | Family: unix |
The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc. Security Fix: * QEMU: slirp: heap buffer overflow during packet reassembly * containers/image: not enforcing TLS when sending username+password credentials to token servers leading to credential disclosure For more details about the security issue, including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page listed in the References section. Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.1 Release Notes linked from the References section.
Platform: |
Red Hat Enterprise Linux 8 |
Product: |
buildah |
container-selinux |
containernetworking-plugins |
fuse-overlayfs |
oci-systemd-hook |
oci-umount |
podman |
runc |
skopeo |
slirp4netns |