First published: Tue Oct 29 2019(Updated: )
Red Hat OpenShift Container Platform is Red Hat's cloud computing<br>Kubernetes application platform solution designed for on-premise or private<br>cloud deployments.<br>The following packages have been rebuilt with an updated version of golang: apb (2.0.3), containernetworking-plugins (0.8.1), and golang-github-prometheus-promu (0.5.0). <br>Security Fix(es):<br><li> HTTP/2: flood using PING frames results in unbounded memory growth (CVE-2019-9512)</li> <li> HTTP/2: flood using HEADERS frames results in unbounded memory growth (CVE-2019-9514)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/apb | <2.0.3-2.el7 | 2.0.3-2.el7 |
redhat/containernetworking-plugins | <0.8.1-4.el7 | 0.8.1-4.el7 |
redhat/golang-github-prometheus-promu | <0.5.0-2.git642a960.el7 | 0.5.0-2.git642a960.el7 |
redhat/apb | <2.0.3-2.el7 | 2.0.3-2.el7 |
redhat/apb-container-scripts | <2.0.3-2.el7 | 2.0.3-2.el7 |
redhat/apb-devel | <2.0.3-2.el7 | 2.0.3-2.el7 |
redhat/containernetworking-plugins | <0.8.1-4.el7 | 0.8.1-4.el7 |
redhat/containernetworking-plugins-debuginfo | <0.8.1-4.el7 | 0.8.1-4.el7 |
redhat/golang-github-prometheus-promu | <0.5.0-2.git642a960.el7 | 0.5.0-2.git642a960.el7 |
redhat/prometheus-promu | <0.5.0-2.git642a960.el7 | 0.5.0-2.git642a960.el7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.