[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

253164

 
 

909

 
 

197077

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

RHSA-2020:1650-01 -- Redhat buildah, cockpit-podman, conmon, container-selinux, containernetworking-plugins, criu, fuse-overlayfs, podman, python-podman-api, runc, skopeo, slirp4netns, toolbox, udica

ID: oval:org.secpod.oval:def:69548Date: (C)2021-03-02   (M)2024-02-19
Class: PATCHFamily: unix




The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc. Security Fix: * runc: volume mount race condition with shared mounts leads to information leak/integrity manipulation * containers/image: Container images read entire image manifest into memory * podman: incorrectly allows existing files in volumes to be overwritten by a container when it is created For more details about the security issue, including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page listed in the References section. Additional Changes: For detailed information on changes in this release, see the CentOS 8.2 Release Notes linked from the References section.

Platform:
Red Hat Enterprise Linux 8
Product:
buildah
cockpit-podman
conmon
container-selinux
containernetworking-plugins
criu
fuse-overlayfs
podman
python-podman-api
runc
skopeo
slirp4netns
toolbox
udica
Reference:
RHSA-2020:1650-01
CVE-2019-19921
CVE-2020-1702
CVE-2020-1726
CVE    3
CVE-2020-1702
CVE-2020-1726
CVE-2019-19921

© SecPod Technologies