ALSA-2024:2549

Source
https://errata.almalinux.org/9/ALSA-2024-2549.html
Import Source
https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux9/ALSA-2024:2549.json
JSON Data
https://api.osv.dev/v1/vulns/ALSA-2024:2549
Related
Published
2024-04-30T00:00:00Z
Modified
2024-05-07T14:54:52Z
Summary
Moderate: skopeo security and bug fix update
Details

The skopeo command lets you inspect images from container image registries, get images and image layers, and use signatures to create and verify files.

Security Fix(es):

  • golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON (CVE-2024-24786)

Bug Fix(es):

  • TRIAGE CVE-2024-24786 skopeo: golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON [almalinux-9] - AlmaLinux 9.4 0day (JIRA:AlmaLinux-28235)
  • skopeo: jose-go: improper handling of highly compressed data [almalinux-9] (JIRA:AlmaLinux-28736)
References

Affected packages

AlmaLinux:9 / skopeo

Package

Name
skopeo

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2:1.14.3-2.el9_4

AlmaLinux:9 / skopeo-tests

Package

Name
skopeo-tests

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2:1.14.3-2.el9_4