[Forgot Password]
Login  Register Subscribe

30389

 
 

423868

 
 

244625

 
 

909

 
 

193379

 
 

277

Paid content will be excluded from the download.


Download | Alert*
OVAL

RHSA-2019:3494-01 -- Redhat buildah, container-selinux, containernetworking-plugins, fuse-overlayfs, oci-systemd-hook, oci-umount, podman, runc, skopeo, slirp4netns

ID: oval:org.secpod.oval:def:66473Date: (C)2020-10-30   (M)2022-10-10
Class: PATCHFamily: unix




The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc. Security Fix: * QEMU: slirp: heap buffer overflow during packet reassembly * containers/image: not enforcing TLS when sending username+password credentials to token servers leading to credential disclosure For more details about the security issue, including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page listed in the References section. Additional Changes: For detailed information on changes in this release, see the CentOS 8.1 Release Notes linked from the References section.

Platform:
CentOS 8
Product:
buildah
container-selinux
containernetworking-plugins
fuse-overlayfs
oci-systemd-hook
oci-umount
podman
runc
skopeo
slirp4netns
Reference:
RHSA-2019:3494-01
CVE-2019-10214
CVE-2019-14378
CVE    2
CVE-2019-10214
CVE-2019-14378
CPE    11
cpe:/a:projectatomic:oci-systemd-hook
cpe:/a:containers:skopeo
cpe:/a:containernetworking:containernetworking-plugins
cpe:/a:libslirp:slirp4netns
...

© SecPod Technologies