ALSA-2019:3403
Dashboard / Vulnerabilities / ALSA-2019:3403
Summary: Important: container-tools:rhel8 security, bug fix, and enhancement update
Details: The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc. Security Fix(es): * QEMU: slirp: heap buffer overflow during packet reassembly (CVE-2019-14378) * containers/image: not enforcing TLS when sending username+password credentials to token servers leading to credential disclosure (CVE-2019-10214) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.
References: https://errata.almalinux.org/8/ALSA-2019-3403.html, https://vulners.com/cve/CVE-2019-10214, https://vulners.com/cve/CVE-2019-14378, https://vulners.com/cve/CVE-2019-9946
Affected packages
Package
Name: oci-systemd-hook
Purl: pkg:rpm/almalinux/oci-systemd-hook
Affected ranges
Type: ECOSYSTEM
Events:
