ALSA-2024:2549
Dashboard / Vulnerabilities / ALSA-2024:2549
Summary: Moderate: skopeo security and bug fix update
Details: The skopeo command lets you inspect images from container image registries, get images and image layers, and use signatures to create and verify files. Security Fix(es): * golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON (CVE-2024-24786) Bug Fix(es): * TRIAGE CVE-2024-24786 skopeo: golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON [almalinux-9] - AlmaLinux 9.4 0day (JIRA:AlmaLinux-28235) * skopeo: jose-go: improper handling of highly compressed data [almalinux-9] (JIRA:AlmaLinux-28736)
References: https://access.redhat.com/errata/RHSA-2024:2549, https://access.redhat.com/security/cve/CVE-2024-24786, https://access.redhat.com/security/cve/CVE-2024-28180, https://bugzilla.redhat.com/2268046, https://bugzilla.redhat.com/2268854, https://errata.almalinux.org/9/ALSA-2024-2549.html
Affected packages
Package
Name: skopeo
Purl: pkg:rpm/almalinux/skopeo
Affected ranges
Type: ECOSYSTEM
Events:
