[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249622

 
 

909

 
 

195549

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

RHSA-2020:4694-01 -- Centos buildah, cockpit-podman, conmon, container-selinux, containernetworking-plugins, criu, crun, fuse-overlayfs, libslirp, oci-seccomp-bpf-hook, podman, python-podman-api, runc, skopeo, slirp4netns, toolbox, udica

ID: oval:org.secpod.oval:def:68023Date: (C)2020-12-23   (M)2023-11-13
Class: PATCHFamily: unix




The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc. Security Fix: * containernetworking/plugins: IPv6 router advertisements allow for MitM attacks on IPv4 clusters * QEMU: slirp: networking out-of-bounds read information disclosure vulnerability * golang.org/x/text: possibility to trigger an infinite loop in encoding/unicode could lead to crash For more details about the security issue, including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page listed in the References section. Additional Changes: For detailed information on changes in this release, see the CentOS 8.3 Release Notes linked from the References section.

Platform:
CentOS 8
Product:
buildah
cockpit-podman
conmon
container-selinux
containernetworking-plugins
criu
crun
fuse-overlayfs
libslirp
oci-seccomp-bpf-hook
podman
python-podman-api
runc
skopeo
slirp4netns
toolbox
udica
Reference:
RHSA-2020:4694-01
CVE-2020-10749
CVE-2020-10756
CVE-2020-14040
CVE    3
CVE-2020-10749
CVE-2020-14040
CVE-2020-10756
CPE    18
cpe:/a:podman:python-podman-api
cpe:/a:containers:skopeo
cpe:/a:oci-seccomp-bpf-hook:oci-seccomp-bpf-hook
cpe:/a:criu:criu
...

© SecPod Technologies