RHSA-2021:0988: Moderate: rhvm-appliance security, bug fix, and enhancement update
The RHV-M Virtual Appliance automates the process of installing and configuring the Red Hat Virtualization Manager. The appliance is available to download as an OVA file from the Customer Portal.The following packages have been upgraded to a later upstream version: rhvm-appliance (4.4). (BZ#1915881)Security Fix(es): lldpd: buffer overflow in the lldpdecode function in daemon/protocols/lldp.c (CVE-2015-8011) postgresql: Uncontrolled search path element in logical replication (CVE-2020-14349) postgresql: Uncontrolled search path element in CREATE EXTENSION (CVE-2020-14350) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2021:0988?
The severity of RHSA-2021:0988 is rated as important.
How do I fix RHSA-2021:0988?
To fix RHSA-2021:0988, upgrade the rhvm-appliance package to version 4.4-20210310.0.el8e or later.
What components are affected by RHSA-2021:0988?
The affected component in RHSA-2021:0988 is the rhvm-appliance package.
What versions of rhvm-appliance are impacted by RHSA-2021:0988?
RHSA-2021:0988 impacts rhvm-appliance versions prior to 4.4-20210310.0.el8e.
Is there a workaround for RHSA-2021:0988?
There are no specific workarounds for RHSA-2021:0988; upgrading the package is recommended.