[Git][security-tracker-team/security-tracker][master] Update information on CVE-2019-10214/singularity-container

Salvatore Bonaccorso carnil at debian.org
Wed Dec 25 21:15:15 GMT 2019



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
1cf64ce7 by Salvatore Bonaccorso at 2019-12-25T21:13:35Z
Update information on CVE-2019-10214/singularity-container

singularity-container since the go rewrite contains a
vendor/github.com/containers/image/docker/docker_client.go which is
since 3.5.0 upstream containing the fix for CVE-2019-10214 from
golang-github-containers-image.

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -35852,7 +35852,7 @@ CVE-2019-10215 (Bootstrap-3-Typeahead after version 4.0.2 is vulnerable to a cro
 	NOT-FOR-US: Bootstrap-3-Typeahead
 CVE-2019-10214 (The containers/image library used by the container tools Podman, Build ...)
 	- golang-github-containers-image <not-affected> (Vulnerable version was never in unstable)
-	- singularity-container <unfixed>
+	- singularity-container 3.5.0+ds1-1
 	NOTE: https://github.com/containers/image/issues/654
 	NOTE: https://github.com/containers/image/pull/669
 CVE-2019-10213 (OpenShift Container Platform, versions 4.1 and 4.2, does not sanitize  ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/1cf64ce701b937fafda5ec70f32f63920c4935a4

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/1cf64ce701b937fafda5ec70f32f63920c4935a4
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20191225/3858e04f/attachment.html>


More information about the debian-security-tracker-commits mailing list