Lucene search

K
redhatRedHatRHSA-2023:6363
HistoryNov 07, 2023 - 6:03 a.m.

(RHSA-2023:6363) Moderate: skopeo security update

2023-11-0706:03:10
access.redhat.com
21
skopeo
security
update
container
images
golang
html/template
net/http
denial of service
cve-2023-24540
cve-2022-41723
cve-2022-41724
cve-2022-41725
cve-2023-24534
cve-2023-24536
cve-2023-24537
cve-2023-24538
cve-2023-24539
cve-2023-29400
cve-2023-29406
red hat enterprise linux 9.3

7.9 High

AI Score

Confidence

High

0.024 Low

EPSS

Percentile

90.0%

The skopeo command lets you inspect images from container image registries, get images and image layers, and use signatures to create and verify files.

Security Fix(es):

  • golang: html/template: improper handling of JavaScript whitespace (CVE-2023-24540)

  • net/http, golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding (CVE-2022-41723)

  • golang: crypto/tls: large handshake records may cause panics (CVE-2022-41724)

  • golang: net/http, mime/multipart: denial of service from excessive resource consumption (CVE-2022-41725)

  • golang: net/http, net/textproto: denial of service from excessive memory allocation (CVE-2023-24534)

  • golang: net/http, net/textproto, mime/multipart: denial of service from excessive resource consumption (CVE-2023-24536)

  • golang: go/parser: Infinite loop in parsing (CVE-2023-24537)

  • golang: html/template: backticks not treated as string delimiters (CVE-2023-24538)

  • golang: html/template: improper sanitization of CSS values (CVE-2023-24539)

  • golang: html/template: improper handling of empty HTML attributes (CVE-2023-29400)

  • golang: net/http: insufficient sanitization of Host header (CVE-2023-29406)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Red Hat Enterprise Linux 9.3 Release Notes linked from the References section.

7.9 High

AI Score

Confidence

High

0.024 Low

EPSS

Percentile

90.0%