openSUSE-SU-2018:0882-1: moderate: Security update for docker-distribution
openSUSE Security Update: Security update for docker-distribution ______________________________________________________________________________ Announcement ID: openSUSE-SU-2018:0882-1 Rating: moderate References: #1033172 #1049850 #1083474 Cross-References: CVE-2017-11468 Affected Products: openSUSE Leap 42.3 ______________________________________________________________________________ An update that solves one vulnerability and has two fixes is now available. Description: This update for docker-distribution fixes the following issues: Security issues fixed: - CVE-2017-11468: Fixed a denial of service (memory consumption) via the manifest endpoint (bsc#1049850). Bug fixes: - bsc#1083474: docker-distirbution-registry overwrites configuration file with update. - bsc#1033172: Garbage collector needed - or kindly release docker-distribution-registry in Version 2.4. - Add SuSEfirewall2 service file for TCP port 5000. This update was imported from the SUSE:SLE-12:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 42.3: zypper in -t patch openSUSE-2018-336=1 Package List: - openSUSE Leap 42.3 (x86_64): docker-distribution-debugsource-2.6.2-11.1 docker-distribution-registry-2.6.2-11.1 docker-distribution-registry-debuginfo-2.6.2-11.1 References: https://www.suse.com/security/cve/CVE-2017-11468.html https://bugzilla.suse.com/1033172 https://bugzilla.suse.com/1049850 https://bugzilla.suse.com/1083474
participants (1)
-
opensuse-security@opensuse.org