First published: Thu Mar 25 2021(Updated: )
The RHV-M Virtual Appliance automates the process of installing and configuring the Red Hat Virtualization Manager. The appliance is available to download as an OVA file from the Customer Portal.<br>The following packages have been upgraded to a later upstream version: rhvm-appliance (4.4). (BZ#1915881)<br>Security Fix(es):<br><li> lldpd: buffer overflow in the lldp_decode function in daemon/protocols/lldp.c (CVE-2015-8011)</li> <li> postgresql: Uncontrolled search path element in logical replication (CVE-2020-14349)</li> <li> postgresql: Uncontrolled search path element in CREATE EXTENSION (CVE-2020-14350)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/rhvm-appliance | <4.4-20210310.0.el8e | 4.4-20210310.0.el8e |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2021:0988 is rated as important.
To fix RHSA-2021:0988, upgrade the rhvm-appliance package to version 4.4-20210310.0.el8e or later.
The affected component in RHSA-2021:0988 is the rhvm-appliance package.
RHSA-2021:0988 impacts rhvm-appliance versions prior to 4.4-20210310.0.el8e.
There are no specific workarounds for RHSA-2021:0988; upgrading the package is recommended.