Advisory Published

RHSA-2020:1227: Moderate: podman security, bug fix, and enhancement update

First published: Tue Mar 31 2020(Updated: )

The podman tool manages pods, container images, and containers. It is part of the libpod library, which is for applications that use container pods. Container pods is a concept in Kubernetes.<br>Security Fix(es):<br><li> podman: resolving symlink in host filesystem leads to unexpected results of copy operation (CVE-2019-18466)</li> <li> containers/image: Container images read entire image manifest into memory (CVE-2020-1702)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>Bug Fix(es):<br><li> [extras-rhel-7] conmon binary stripped but debuginfo not generated (BZ#1650395)</li> <li> Cannot run systemd-container with SCL service due to RHSA-2019:2091 fix (BZ#1758509)</li> <li> Podman does not enforce registries.block in the registries.conf file (BZ#1787666)</li> <li> podman and podman-manpages needs merging (BZ#1788549)</li> <li> podman should be linked against gpgme-pthread (BZ#1793083)</li> <li> podman cannot support load tarball which the name with colon but docker can support this (BZ#1797599)</li> <li> podman (1.6.4) rhel 8.1 no route to host from inside container [extras-rhel-7.8/podman] (BZ#1806895)</li> <li> Podman can't reuse a container name, even if the container that was using it is no longer around [extras-rhel-7.8/podman] (BZ#1807437)</li> <li> podman exec does not reads from stdin [extras-rhel-7.8/podman] (BZ#1807586)</li> <li> [FJ8.2 Bug]: [REG]The "--group-add" option of "podman create" doesn't function. [extras-rhel-7.8/podman] (BZ#1808702)</li> Enhancement(s):<br><li> [RFE] sctp support for podman (BZ#1664218)</li>

Affected SoftwareAffected VersionHow to fix
redhat/podman<1.6.4-16.el7_8
1.6.4-16.el7_8
redhat/podman<1.6.4-16.el7_8
1.6.4-16.el7_8
redhat/podman-debuginfo<1.6.4-16.el7_8
1.6.4-16.el7_8
redhat/podman-docker<1.6.4-16.el7_8
1.6.4-16.el7_8
redhat/podman-debuginfo<1.6.4-16.el7_8
1.6.4-16.el7_8
redhat/podman<1.6.4-16.el7_8
1.6.4-16.el7_8
redhat/podman-debuginfo<1.6.4-16.el7_8
1.6.4-16.el7_8

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203