Lucene search

K
osvGoogleOSV:RLSA-2019:3494
HistoryNov 05, 2019 - 5:52 p.m.

Important: container-tools:1.0 security and bug fix update

2019-11-0517:52:13
Google
osv.dev
5

9.1 High

AI Score

Confidence

High

0.017 Low

EPSS

Percentile

87.7%

The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.

Security Fix(es):

  • QEMU: slirp: heap buffer overflow during packet reassembly (CVE-2019-14378)

  • containers/image: not enforcing TLS when sending username+password credentials to token servers leading to credential disclosure (CVE-2019-10214)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Rocky Linux 8.1 Release Notes linked from the References section.