RHSA-2024:7374LowCVSS 8.8
Red Hat Security Advisory: Security update for service-interconnect rhel9 container images
🔗 CVE IDs covered (6)
📋 Description
CVE-2024-2398 — curl: HTTP/2 push headers memory-leak CVE-2024-6345 — pypa/setuptools: Remote code execution via download functions in the package_index module in pypa/setuptools CVE-2024-6923 — cpython: python: email module doesn't properly quotes newlines in email headers, allowing header injection CVE-2024-34397 — glib2: Signal subscription vulnerabilities CVE-2024-37370 — krb5: GSS message token handling CVE-2024-37371 — krb5: GSS message token handling
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2024:7374
- externalhttps://access.redhat.com/security/updates/classification/#low
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2270498
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2279632
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2294676
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2294677
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2297771
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2302255
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_7374.json