First published: Tue May 12 2020(Updated: )
The podman tool manages pods, container images, and containers. It is part of the libpod library, which is for applications that use container pods. Container pods is a concept in Kubernetes.<br>Security Fix(es):<br><li> buildah: Crafted input tar file may lead to local file overwrite during image build process (CVE-2020-10696)</li> <li> proglottis/gpgme: Use-after-free in GPGME bindings during container image pull (CVE-2020-8945)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/podman | <1.6.4-18.el7_8 | 1.6.4-18.el7_8 |
redhat/podman | <1.6.4-18.el7_8 | 1.6.4-18.el7_8 |
redhat/podman-debuginfo | <1.6.4-18.el7_8 | 1.6.4-18.el7_8 |
redhat/podman-docker | <1.6.4-18.el7_8 | 1.6.4-18.el7_8 |
redhat/podman-debuginfo | <1.6.4-18.el7_8 | 1.6.4-18.el7_8 |
redhat/podman | <1.6.4-18.el7_8 | 1.6.4-18.el7_8 |
redhat/podman-debuginfo | <1.6.4-18.el7_8 | 1.6.4-18.el7_8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
RHSA-2020:2117 has been classified as an important security issue.
To fix RHSA-2020:2117, update the affected podman package to version 1.6.4-18.el7_8.
RHSA-2020:2117 addresses vulnerabilities associated with crafted tar file inputs leading to local file overwrites.
Affected packages include podman, podman-docker, and podman-debuginfo for various architectures.
RHSA-2020:2117 is applicable to systems running the specified versions of affected Red Hat packages.