MGASA-2020-0103

Source
https://advisories.mageia.org/MGASA-2020-0103.html
Import Source
https://advisories.mageia.org/MGASA-2020-0103.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2020-0103
Related
Published
2020-02-26T10:21:01Z
Modified
2020-02-26T10:00:28Z
Summary
Updated opencontainers-runc packages fix security vulnerability
Details

Updated opencontainers-runc package fixes security vulnerability:

An attacker who controls the container image for two containers that share a volume can race volume mounts during container initialization, by adding a symlink to the rootfs that points to a directory on the volume (CVE-2019-19921).

References
Credits

Affected packages

Mageia:7 / opencontainers-runc

Package

Name
opencontainers-runc
Purl
pkg:rpm/mageia/opencontainers-runc?distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.0.0-0.rc10.3.1.mga7

Ecosystem specific

{
    "section": "core"
}