RHSA-2019:3494HighCVSS 7.0
Red Hat Security Advisory: container-tools:1.0 security and bug fix update
🔗 CVE IDs covered (2)
📋 Description
CVE-2019-10214 — containers/image: not enforcing TLS when sending username+password credentials to token servers leading to credential disclosure CVE-2019-14378 — QEMU: slirp: heap buffer overflow during packet reassembly
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2019:3494
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.1_release_notes/
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1700877
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1732508
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1734745
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2019/rhsa-2019_3494.json