[ALSA-2023:2283] skopeo security and bug fix update

Severity Moderate
Affected Packages 4
CVEs 2

skopeo security and bug fix update

The skopeo command lets you inspect images from container image registries, get images and image layers, and use signatures to create and verify files.

Security Fix(es):

  • golang: net/http: excessive memory growth in a Go server accepting HTTP/2 requests (CVE-2022-41717)
  • golang: crypto/tls: session tickets lack random ticket_age_add (CVE-2022-30629)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.

ID
ALSA-2023:2283
Severity
moderate
URL
https://errata.almalinux.org/ALSA-2023:2283.html
Published
2023-05-09T00:00:00
(16 months ago)
Modified
2023-05-12T07:32:56
(16 months ago)
Rights
Copyright 2023 AlmaLinux OS
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/almalinux/skopeo?arch=x86_64&distro=almalinux-9 almalinux skopeo < 1.11.2-0.1.el9 almalinux-9 x86_64
Affected pkg:rpm/almalinux/skopeo?arch=aarch64&distro=almalinux-9 almalinux skopeo < 1.11.2-0.1.el9 almalinux-9 aarch64
Affected pkg:rpm/almalinux/skopeo-tests?arch=x86_64&distro=almalinux-9 almalinux skopeo-tests < 1.11.2-0.1.el9 almalinux-9 x86_64
Affected pkg:rpm/almalinux/skopeo-tests?arch=aarch64&distro=almalinux-9 almalinux skopeo-tests < 1.11.2-0.1.el9 almalinux-9 aarch64
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...