Vulnerability Database
Blog
FAQ
Docs
RHSA-2019:0975
See a problem?
Please try reporting it
to the source
first.
Source
https://access.redhat.com/errata/RHSA-2019:0975
Import Source
https://security.access.redhat.com/data/osv/RHSA-2019:0975.json
JSON Data
https://api.osv.dev/v1/vulns/RHSA-2019:0975
Related
CVE-2019-5736
Published
2024-09-13T14:07:56Z
Modified
2024-09-13T14:07:56Z
Severity
7.7 (High)
CVSS_V3 - CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
CVSS Calculator
Summary
Red Hat Security Advisory: container-tools:rhel8 security and bug fix update
Details
References
https://access.redhat.com/errata/RHSA-2019:0975
https://access.redhat.com/security/updates/classification/#important
https://bugzilla.redhat.com/show_bug.cgi?id=1664908
https://bugzilla.redhat.com/show_bug.cgi?id=1693675
https://bugzilla.redhat.com/show_bug.cgi?id=1695669
https://bugzilla.redhat.com/show_bug.cgi?id=1695689
https://access.redhat.com/security/data/csaf/v2/advisories/2019/rhsa-2019_0975.json
https://access.redhat.com/security/cve/CVE-2019-5736
https://www.cve.org/CVERecord?id=CVE-2019-5736
https://nvd.nist.gov/vuln/detail/CVE-2019-5736
https://blog.dragonsector.pl/2019/02/cve-2019-5736-escape-from-docker-and.html
https://seclists.org/oss-sec/2019/q1/119
Affected packages
Red Hat:enterprise_linux:8::appstream
/
buildah
Package
Name
buildah
Purl
pkg:rpm/redhat/buildah
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.5-3.gite94b4f9.module+el8.0.0+2958+4e823551
Red Hat:enterprise_linux:8::appstream
/
buildah-debuginfo
Package
Name
buildah-debuginfo
Purl
pkg:rpm/redhat/buildah-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.5-3.gite94b4f9.module+el8.0.0+2958+4e823551
Red Hat:enterprise_linux:8::appstream
/
buildah-debugsource
Package
Name
buildah-debugsource
Purl
pkg:rpm/redhat/buildah-debugsource
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.5-3.gite94b4f9.module+el8.0.0+2958+4e823551
Red Hat:enterprise_linux:8::appstream
/
container-selinux
Package
Name
container-selinux
Purl
pkg:rpm/redhat/container-selinux
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
2:2.94-1.git1e99f1d.module+el8.0.0+2958+4e823551
Red Hat:enterprise_linux:8::appstream
/
containernetworking-plugins
Package
Name
containernetworking-plugins
Purl
pkg:rpm/redhat/containernetworking-plugins
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:0.7.4-3.git9ebe139.module+el8.0.0+2958+4e823551
Red Hat:enterprise_linux:8::appstream
/
containernetworking-plugins-debuginfo
Package
Name
containernetworking-plugins-debuginfo
Purl
pkg:rpm/redhat/containernetworking-plugins-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:0.7.4-3.git9ebe139.module+el8.0.0+2958+4e823551
Red Hat:enterprise_linux:8::appstream
/
containernetworking-plugins-debugsource
Package
Name
containernetworking-plugins-debugsource
Purl
pkg:rpm/redhat/containernetworking-plugins-debugsource
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:0.7.4-3.git9ebe139.module+el8.0.0+2958+4e823551
Red Hat:enterprise_linux:8::appstream
/
containers-common
Package
Name
containers-common
Purl
pkg:rpm/redhat/containers-common
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1:0.1.32-3.git1715c90.module+el8.0.0+2958+4e823551
Red Hat:enterprise_linux:8::appstream
/
fuse-overlayfs
Package
Name
fuse-overlayfs
Purl
pkg:rpm/redhat/fuse-overlayfs
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:0.3-2.module+el8.0.0+2958+4e823551
Red Hat:enterprise_linux:8::appstream
/
fuse-overlayfs-debuginfo
Package
Name
fuse-overlayfs-debuginfo
Purl
pkg:rpm/redhat/fuse-overlayfs-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:0.3-2.module+el8.0.0+2958+4e823551
Red Hat:enterprise_linux:8::appstream
/
fuse-overlayfs-debugsource
Package
Name
fuse-overlayfs-debugsource
Purl
pkg:rpm/redhat/fuse-overlayfs-debugsource
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:0.3-2.module+el8.0.0+2958+4e823551
Red Hat:enterprise_linux:8::appstream
/
oci-systemd-hook
Package
Name
oci-systemd-hook
Purl
pkg:rpm/redhat/oci-systemd-hook
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1:0.1.15-2.git2d0b8a3.module+el8.0.0+2958+4e823551
Red Hat:enterprise_linux:8::appstream
/
oci-systemd-hook-debuginfo
Package
Name
oci-systemd-hook-debuginfo
Purl
pkg:rpm/redhat/oci-systemd-hook-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1:0.1.15-2.git2d0b8a3.module+el8.0.0+2958+4e823551
Red Hat:enterprise_linux:8::appstream
/
oci-systemd-hook-debugsource
Package
Name
oci-systemd-hook-debugsource
Purl
pkg:rpm/redhat/oci-systemd-hook-debugsource
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1:0.1.15-2.git2d0b8a3.module+el8.0.0+2958+4e823551
Red Hat:enterprise_linux:8::appstream
/
oci-umount
Package
Name
oci-umount
Purl
pkg:rpm/redhat/oci-umount
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
2:2.3.4-2.git87f9237.module+el8.0.0+2958+4e823551
Red Hat:enterprise_linux:8::appstream
/
oci-umount-debuginfo
Package
Name
oci-umount-debuginfo
Purl
pkg:rpm/redhat/oci-umount-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
2:2.3.4-2.git87f9237.module+el8.0.0+2958+4e823551
Red Hat:enterprise_linux:8::appstream
/
oci-umount-debugsource
Package
Name
oci-umount-debugsource
Purl
pkg:rpm/redhat/oci-umount-debugsource
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
2:2.3.4-2.git87f9237.module+el8.0.0+2958+4e823551
Red Hat:enterprise_linux:8::appstream
/
podman
Package
Name
podman
Purl
pkg:rpm/redhat/podman
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.0.0-2.git921f98f.module+el8.0.0+2958+4e823551
Red Hat:enterprise_linux:8::appstream
/
podman-debuginfo
Package
Name
podman-debuginfo
Purl
pkg:rpm/redhat/podman-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.0.0-2.git921f98f.module+el8.0.0+2958+4e823551
Red Hat:enterprise_linux:8::appstream
/
podman-debugsource
Package
Name
podman-debugsource
Purl
pkg:rpm/redhat/podman-debugsource
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.0.0-2.git921f98f.module+el8.0.0+2958+4e823551
Red Hat:enterprise_linux:8::appstream
/
podman-docker
Package
Name
podman-docker
Purl
pkg:rpm/redhat/podman-docker
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.0.0-2.git921f98f.module+el8.0.0+2958+4e823551
Red Hat:enterprise_linux:8::appstream
/
runc
Package
Name
runc
Purl
pkg:rpm/redhat/runc
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.0.0-55.rc5.dev.git2abd837.module+el8.0.0+3049+59fd2bba
Red Hat:enterprise_linux:8::appstream
/
runc-debuginfo
Package
Name
runc-debuginfo
Purl
pkg:rpm/redhat/runc-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.0.0-55.rc5.dev.git2abd837.module+el8.0.0+3049+59fd2bba
Red Hat:enterprise_linux:8::appstream
/
runc-debugsource
Package
Name
runc-debugsource
Purl
pkg:rpm/redhat/runc-debugsource
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.0.0-55.rc5.dev.git2abd837.module+el8.0.0+3049+59fd2bba
Red Hat:enterprise_linux:8::appstream
/
skopeo
Package
Name
skopeo
Purl
pkg:rpm/redhat/skopeo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1:0.1.32-3.git1715c90.module+el8.0.0+2958+4e823551
Red Hat:enterprise_linux:8::appstream
/
skopeo-debuginfo
Package
Name
skopeo-debuginfo
Purl
pkg:rpm/redhat/skopeo-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1:0.1.32-3.git1715c90.module+el8.0.0+2958+4e823551
Red Hat:enterprise_linux:8::appstream
/
skopeo-debugsource
Package
Name
skopeo-debugsource
Purl
pkg:rpm/redhat/skopeo-debugsource
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1:0.1.32-3.git1715c90.module+el8.0.0+2958+4e823551
Red Hat:enterprise_linux:8::appstream
/
slirp4netns
Package
Name
slirp4netns
Purl
pkg:rpm/redhat/slirp4netns
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:0.1-2.dev.gitc4e1bc5.module+el8.0.0+2958+4e823551
Red Hat:enterprise_linux:8::appstream
/
slirp4netns-debuginfo
Package
Name
slirp4netns-debuginfo
Purl
pkg:rpm/redhat/slirp4netns-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:0.1-2.dev.gitc4e1bc5.module+el8.0.0+2958+4e823551
Red Hat:enterprise_linux:8::appstream
/
slirp4netns-debugsource
Package
Name
slirp4netns-debugsource
Purl
pkg:rpm/redhat/slirp4netns-debugsource
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:0.1-2.dev.gitc4e1bc5.module+el8.0.0+2958+4e823551
RHSA-2019:0975 - OSV