First published: Wed Apr 22 2020(Updated: )
Red Hat OpenShift Container Platform is Red Hat's cloud computing<br>Kubernetes application platform solution designed for on-premise or private<br>cloud deployments.<br>Security Fix(es):<br><li> buildah: a crafted input tar file could overwrite local files during the image build process (CVE-2020-10696)</li> For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE<br>page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/podman | <1.0.2-4.dev.git96ccc2e.rhaos4.1.el8 | 1.0.2-4.dev.git96ccc2e.rhaos4.1.el8 |
redhat/podman | <1.0.2-4.dev.git96ccc2e.rhaos4.1.el8 | 1.0.2-4.dev.git96ccc2e.rhaos4.1.el8 |
redhat/podman-docker | <1.0.2-4.dev.git96ccc2e.rhaos4.1.el8 | 1.0.2-4.dev.git96ccc2e.rhaos4.1.el8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2020:1449 is classified as low.
To fix RHSA-2020:1449, update to the remedied version 1.0.2-4.dev.git96ccc2e.rhaos4.1.el8 of the affected packages.
RHSA-2020:1449 addresses a vulnerability in buildah that allows a crafted input tar file to overwrite local files during image builds.
RHSA-2020:1449 affects the podman and podman-docker packages.
RHSA-2020:1449 was released on April 28, 2020.