RHSA-2021:0988MediumCVSS 9.8
Red Hat Security Advisory: rhvm-appliance security, bug fix, and enhancement update
🔗 CVE IDs covered (3)
📋 Description
CVE-2015-8011 — lldpd: buffer overflow in the lldp_decode function in daemon/protocols/lldp.c CVE-2020-14349 — postgresql: Uncontrolled search path element in logical replication CVE-2020-14350 — postgresql: Uncontrolled search path element in CREATE EXTENSION
🎯 Affected products6
- Red Hat Virtualization 4 Hypervisor for RHEL 8
- Red Hat Virtualization 4 Management Agent for RHEL 7 Hosts
- rhvm-appliance-2:4.4-20210310.0.el8ev.src as a component of Red Hat Virtualization 4 Hypervisor for RHEL 8
- rhvm-appliance-2:4.4-20210310.0.el8ev.src as a component of Red Hat Virtualization 4 Management Agent for RHEL 7 Hosts
- rhvm-appliance-2:4.4-20210310.0.el8ev.x86_64 as a component of Red Hat Virtualization 4 Hypervisor for RHEL 8
- rhvm-appliance-2:4.4-20210310.0.el8ev.x86_64 as a component of Red Hat Virtualization 4 Management Agent for RHEL 7 Hosts
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/2974891 Workaround: When the lldpd source is compiled with source fortification enabled, the flaw becomes unexploitable and will just cause a crash.
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2021:0988
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1865744
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1865746
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1896536
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1915881
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_0988.json