[Bug 1143409] VUL-1: CVE-2019-14271: docker: code injection can occur when the nsswitch facility dynamically loads a library inside a chroot that contains the contents of the container
http://bugzilla.suse.com/show_bug.cgi?id=1143409 http://bugzilla.suse.com/show_bug.cgi?id=1143409#c4 --- Comment #4 from Swamp Workflow Management <swamp@suse.de> --- SUSE-SU-2019:2119-1: An update that solves four vulnerabilities and has one errata is now available. Category: security (important) Bug References: 1100331,1121967,1142160,1142413,1143409 CVE References: CVE-2018-10892,CVE-2019-13509,CVE-2019-14271,CVE-2019-5736 Sources used: SUSE OpenStack Cloud 6-LTSS (src): containerd-1.2.6-16.23.1, docker-19.03.1_ce-98.46.1, docker-runc-1.0.0rc8+gitr3826_425e105d5a03-1.29.1, golang-github-docker-libnetwork-0.7.0.1+gitr2800_fc5a7d91d54c-25.1 SUSE Linux Enterprise Module for Containers 12 (src): containerd-1.2.6-16.23.1, docker-19.03.1_ce-98.46.1, docker-runc-1.0.0rc8+gitr3826_425e105d5a03-1.29.1, golang-github-docker-libnetwork-0.7.0.1+gitr2800_fc5a7d91d54c-25.1 SUSE CaaS Platform 3.0 (src): containerd-kubic-1.2.6-16.23.1, docker-kubic-19.03.1_ce-98.46.1, docker-runc-kubic-1.0.0rc8+gitr3826_425e105d5a03-1.29.1, golang-github-docker-libnetwork-kubic-0.7.0.1+gitr2800_fc5a7d91d54c-25.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination. -- You are receiving this mail because: You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@novell.com