skopeo-0.1.40-11.0.1.el7.AXS7

エラータID: AXSA:2020-198:02

Release date: 
Thursday, July 2, 2020 - 04:07
Subject: 
skopeo-0.1.40-11.0.1.el7.AXS7
Affected Channels: 
Asianux Server 7 for x86_64
Severity: 
Low
Description: 

The skopeo command lets you inspect images from container image registries, get images and image layers, and use signatures to create and verify files.

Security Fix(es):

* containers/image: Container images read entire image manifest into memory (CVE-2020-1702)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Bug Fix(es):

* Proposed registries.conf

CVE-2020-1702
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. skopeo-0.1.40-11.0.1.el7.AXS7.src.rpm
    MD5: 4ea9ddc2c93c340416dcb6ed8cb278f0
    SHA-256: 584b2f121603713c0bc359dd8c29aafd01caabb8b78aa40c4b8dbb36d259cb0f
    Size: 3.69 MB

Asianux Server 7 for x86_64
  1. containers-common-0.1.40-11.0.1.el7.AXS7.x86_64.rpm
    MD5: 4004658dc829a94becb767b6833296e2
    SHA-256: b023aa825b4f9146c4bf8e3f3b8af583f4f566d91e11ae5c3cb4462f4ea45364
    Size: 42.62 kB
  2. skopeo-0.1.40-11.0.1.el7.AXS7.x86_64.rpm
    MD5: 5b23b393dae68b188fe47b184cdbd566
    SHA-256: cf0bb8faec3153441f1137b370bcf62999a489612992c67ac7fa857514a82f64
    Size: 5.79 MB