Lucene search

K
osvGoogleOSV:ALSA-2019:3403
HistoryNov 05, 2019 - 5:41 p.m.

Important: container-tools:rhel8 security, bug fix, and enhancement update

2019-11-0517:41:57
Google
osv.dev
6

9.1 High

AI Score

Confidence

High

0.017 Low

EPSS

Percentile

87.7%

The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.

Security Fix(es):

  • QEMU: slirp: heap buffer overflow during packet reassembly (CVE-2019-14378)

  • containers/image: not enforcing TLS when sending username+password credentials to token servers leading to credential disclosure (CVE-2019-10214)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.