Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

openSUSE: 2020:2063-1 Moderate: Podman Environment Leak

opensuse
Calendar Grey November 27, 2020
Dist Opensuse Esm H88
An update to openSUSE addresses a significant security issue in Podman, resolving leaks of environment variables while boosting overall efficiency.
An update that solves one vulnerability and has two fixes is now available

Description

This update for podman fixes the following issues:

Security issue fixed:

- This release resolves CVE-2020-14370, in which environment variables

could be leaked between containers created using the Varlink API

(bsc#1176804).

Non-security issues fixed:

- add dependency to timezone package or podman fails to build a container

(bsc#1178122)

- Install new auto-update system units

- Update to v2.1.1 (bsc#1178392):

* Changes

- The `podman info` command now includes the cgroup manager Podman is

using.

* API

- The REST API now includes a Server header in all responses.

- Fixed a bug where the Libpod and Compat Attach endpoints could

terminate early, before sending all output from the container.

- Fixed a bug where the Compat Create endpoint for containers did not

properly handle the Interactive parameter.

- Fixed a bug where the Compat Kill endpoint for...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.2:

zypper in -t patch openSUSE-2020-2063=1

Package List

- openSUSE Leap 15.2 (noarch):

podman-cni-config-2.1.1-lp152.4.6.1

- openSUSE Leap 15.2 (x86_64):

podman-2.1.1-lp152.4.6.1

References

https://www.suse.com/security/cve/CVE-2020-14370.html

https://bugzilla.suse.com/1176804

https://bugzilla.suse.com/1178122

https://bugzilla.suse.com/1178392

openSUSE Security Announce mailing list -- security-announce@lists.opensuse.org

To unsubscribe, email security-announce-leave@lists.opensuse.org

List Netiquette:

List Archives:

Announcement ID: openSUSE-SU-2020:2063-1
Rating: moderate
Affected Products: openSUSE Leap 15.2 able.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here