First published: Tue May 12 2020(Updated: )
The buildah package provides a tool for facilitating building OCI container images. Among other things, buildah enables you to: Create a working container, either from scratch or using an image as a starting point; Create an image, either from a working container or using the instructions in a Dockerfile; Build both Docker and OCI images.<br>Security Fix(es):<br><li> buildah: Crafted input tar file may lead to local file overwrite during image build process (CVE-2020-10696)</li> <li> containers/image: Container images read entire image manifest into memory (CVE-2020-1702)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>Bug Fix(es):<br><li> buildah is not expanding env vars in file paths (BZ#1822031)</li>
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/buildah | <1.11.6-11.el7_8 | 1.11.6-11.el7_8 |
redhat/buildah | <1.11.6-11.el7_8 | 1.11.6-11.el7_8 |
redhat/buildah-debuginfo | <1.11.6-11.el7_8 | 1.11.6-11.el7_8 |
redhat/buildah-debuginfo | <1.11.6-11.el7_8 | 1.11.6-11.el7_8 |
redhat/buildah | <1.11.6-11.el7_8 | 1.11.6-11.el7_8 |
redhat/buildah-debuginfo | <1.11.6-11.el7_8 | 1.11.6-11.el7_8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.