RHSA-2020:1230: Moderate: skopeo security and bug fix update
The skopeo command lets you inspect images from container image registries, get images and image layers, and use signatures to create and verify files.Security Fix(es): proglottis/gpgme: Use-after-free in GPGME bindings during container image pull (CVE-2020-8945) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): Skopeo doesn't handle HTTP 429 errors properly (BZ#1752775) skopeo does not show manifest manifest.list.v2 for special cases (BZ#1754905) skopeo inspect results in panic: runtime error: invalid memory address or nil pointer dereference (BZ#1769575) skopeo should be linked against gpgme-pthread (BZ#1793080) docker won't start because registries service won't start (BZ#1812505)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:1230?
The severity of RHSA-2020:1230 is classified as important.
How do I fix RHSA-2020:1230?
To fix RHSA-2020:1230, upgrade the affected packages to version 0.1.40-7.el7_8 or later.
What vulnerabilities are addressed in RHSA-2020:1230?
RHSA-2020:1230 addresses a use-after-free vulnerability in GPGME bindings during container image pull identified as CVE-2020-8945.
Which versions of skopeo are affected by RHSA-2020:1230?
Versions of skopeo prior to 0.1.40-7.el7_8 are affected by RHSA-2020:1230.
Is RHSA-2020:1230 applicable to containers-common?
Yes, RHSA-2020:1230 is applicable to the containers-common package, affecting similar versions.