Red Hat Bug Fix Advisory: Red Hat Ansible Tower 3.8.4-1 - Container
🔗 CVE IDs covered (4)
📋 Description
CVE-2021-23017 — nginx: Off-by-one in ngx_resolver_copy() when labels are followed by a pointer to a root domain name CVE-2021-31535 — libX11: missing request length checks CVE-2021-32027 — postgresql: Buffer overrun from integer overflow in array subscripting calculations CVE-2021-32028 — postgresql: Memory disclosure in INSERT ... ON CONFLICT ... DO UPDATE
🎯 Affected products2
- Red Hat Ansible Tower 3.8 for RHEL 7
- ansible-tower-38/ansible-tower-rhel7@sha256:5bde31ed06a473f6326390136b04b56e5cab05aa457b9592b1977167d0a45a02_amd64 as a component of Red Hat Ansible Tower 3.8 for RHEL 7
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: xterm should not be used to display less trusted data, e.g. from SSH connections to less trusted remote machines. To avoid attacks via .Xdefaults on kiosk type machines, where graphical user has no permission to execute arbitrary operating system commands or sometimes not even to send hardware keyboard keystrokes, the .Xdefaults must not be modifiable by the user. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update as soon as possible.