Oval Definition:oval:org.opensuse.security:def:52273
Revision Date:2020-12-01Version:1
Title:Security update for containerd, docker, docker-runc, golang-github-docker-libnetwork (Moderate)
Description:

This update for containerd, docker, docker-runc, golang-github-docker-libnetwork fixes the following issues:

Security issue fixed:

- CVE-2019-16884: Fixed incomplete patch for LSM bypass via malicious Docker image that mount over a /proc directory (bsc#1152308).

Bug fixes:

- Update to Docker 19.03.5-ce (bsc#1158590). - Update to Docker 19.03.3-ce (bsc#1153367). - Update to Docker 19.03.2-ce (bsc#1150397). - Fixed default installation such that --userns-remap=default works properly (bsc#1143349). - Fixed nginx blocked by apparmor (bsc#1122469).
Family:unixClass:patch
Status:Reference(s):1015173
1122469
1143349
1150397
1152308
1153367
1158590
1162629
1162632
1165280
1165289
1167244
1168938
1171928
1174910
1174913
1176086
1176181
1176671
CVE-2009-0163
CVE-2009-1886
CVE-2009-1888
CVE-2009-2694
CVE-2009-2703
CVE-2009-2813
CVE-2009-2820
CVE-2009-2906
CVE-2009-2948
CVE-2009-3026
CVE-2009-3083
CVE-2009-3084
CVE-2009-3085
CVE-2009-3553
CVE-2009-3615
CVE-2010-0013
CVE-2010-0277
CVE-2010-0393
CVE-2010-0420
CVE-2010-0423
CVE-2010-0540
CVE-2010-0542
CVE-2010-0547
CVE-2010-0728
CVE-2010-0787
CVE-2010-0926
CVE-2010-1624
CVE-2010-1635
CVE-2010-1642
CVE-2010-1748
CVE-2010-2063
CVE-2010-2528
CVE-2010-2941
CVE-2010-3069
CVE-2010-3711
CVE-2011-0719
CVE-2011-1091
CVE-2011-1521
CVE-2011-2522
CVE-2011-2694
CVE-2011-3389
CVE-2011-3594
CVE-2011-4944
CVE-2012-0817
CVE-2012-0845
CVE-2012-0870
CVE-2012-1150
CVE-2012-1182
CVE-2012-2111
CVE-2012-2214
CVE-2012-2669
CVE-2012-3374
CVE-2012-5519
CVE-2012-5532
CVE-2012-6094
CVE-2012-6150
CVE-2012-6152
CVE-2013-0172
CVE-2013-0213
CVE-2013-0214
CVE-2013-0271
CVE-2013-0272
CVE-2013-0273
CVE-2013-0274
CVE-2013-0454
CVE-2013-1752
CVE-2013-1753
CVE-2013-1863
CVE-2013-4124
CVE-2013-4238
CVE-2013-4408
CVE-2013-4475
CVE-2013-4476
CVE-2013-4496
CVE-2013-4509
CVE-2013-6442
CVE-2013-6477
CVE-2013-6478
CVE-2013-6479
CVE-2013-6481
CVE-2013-6482
CVE-2013-6483
CVE-2013-6484
CVE-2013-6485
CVE-2013-6486
CVE-2013-6487
CVE-2014-0020
CVE-2014-0178
CVE-2014-0239
CVE-2014-0244
CVE-2014-1912
CVE-2014-2856
CVE-2014-3493
CVE-2014-3537
CVE-2014-3560
CVE-2014-3694
CVE-2014-3695
CVE-2014-3696
CVE-2014-3697
CVE-2014-3698
CVE-2014-4650
CVE-2014-5029
CVE-2014-5030
CVE-2014-5031
CVE-2014-7185
CVE-2014-7300
CVE-2014-9474
CVE-2014-9679
CVE-2015-1158
CVE-2015-1159
CVE-2015-3451
CVE-2016-9918
CVE-2019-16884
CVE-2020-10663
CVE-2020-10933
CVE-2020-14361
CVE-2020-14362
CVE-2020-24659
CVE-2020-7059
CVE-2020-7060
CVE-2020-7062
CVE-2020-7063
CVE-2020-9484
SUSE-SU-2019:0841-1
SUSE-SU-2020:0035-1
SUSE-SU-2020:0622-1
SUSE-SU-2020:0995-1
SUSE-SU-2020:1364-1
SUSE-SU-2020:2452-1
SUSE-SU-2020:2988-1
Platform(s):openSUSE Leap 15.0
SUSE Linux Enterprise Desktop 11 SP2
SUSE Linux Enterprise Desktop 11 SP4
SUSE Linux Enterprise Desktop 12
SUSE Linux Enterprise Desktop 12 SP1
SUSE Linux Enterprise Desktop 12 SP3
SUSE Linux Enterprise Desktop 12 SP4
SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 SP1
SUSE Linux Enterprise Server 12 SP1
SUSE Linux Enterprise Server 12 SP1-LTSS
SUSE Linux Enterprise Server 12 SP2
SUSE Linux Enterprise Server 12 SP2-BCL
SUSE Linux Enterprise Server 12 SP2-ESPOS
SUSE Linux Enterprise Server 12 SP2-LTSS
SUSE Linux Enterprise Server 12 SP3
SUSE Linux Enterprise Server 12 SP3-BCL
SUSE Linux Enterprise Server 12 SP3-ESPOS
SUSE Linux Enterprise Server 12 SP3-LTSS
SUSE Linux Enterprise Server 12 SP3-TERADATA
SUSE Linux Enterprise Server 12 SP4
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Workstation Extension 15
SUSE Linux Enterprise Workstation Extension 15 SP2
SUSE OpenStack Cloud 7
SUSE OpenStack Cloud 8
SUSE OpenStack Cloud Crowbar 8
Product(s):
Definition Synopsis
  • openSUSE Leap 15.0 is installed
  • AND Package Information
  • bind-9.11.2-lp150.7 is installed
  • OR bind-chrootenv-9.11.2-lp150.7 is installed
  • OR bind-utils-9.11.2-lp150.7 is installed
  • OR libbind9-160-9.11.2-lp150.7 is installed
  • OR libdns169-9.11.2-lp150.7 is installed
  • OR libirs160-9.11.2-lp150.7 is installed
  • OR libisc166-9.11.2-lp150.7 is installed
  • OR libisccc160-9.11.2-lp150.7 is installed
  • OR libisccfg160-9.11.2-lp150.7 is installed
  • OR liblwres160-9.11.2-lp150.7 is installed
  • OR python3-bind-9.11.2-lp150.7 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 11 SP2 is installed
  • AND Package Information
  • libmysqlclient15-5.0.96-0.6 is installed
  • OR libmysqlclient15-32bit-5.0.96-0.6 is installed
  • OR libmysqlclient_r15-5.0.96-0.6 is installed
  • OR libmysqlclient_r15-32bit-5.0.96-0.6 is installed
  • OR mysql-5.0.96-0.6 is installed
  • OR mysql-client-5.0.96-0.6 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 11 SP4 is installed
  • AND Package Information
  • gnutls-2.4.1-24.39.57 is installed
  • OR libgnutls26-2.4.1-24.39.57 is installed
  • OR libgnutls26-32bit-2.4.1-24.39.57 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 12 is installed
  • AND Package Information
  • libdcerpc-binding0-4.1.12-3 is installed
  • OR libdcerpc-binding0-32bit-4.1.12-3 is installed
  • OR libdcerpc0-4.1.12-3 is installed
  • OR libdcerpc0-32bit-4.1.12-3 is installed
  • OR libgensec0-4.1.12-3 is installed
  • OR libgensec0-32bit-4.1.12-3 is installed
  • OR libndr-krb5pac0-4.1.12-3 is installed
  • OR libndr-krb5pac0-32bit-4.1.12-3 is installed
  • OR libndr-nbt0-4.1.12-3 is installed
  • OR libndr-nbt0-32bit-4.1.12-3 is installed
  • OR libndr-standard0-4.1.12-3 is installed
  • OR libndr-standard0-32bit-4.1.12-3 is installed
  • OR libndr0-4.1.12-3 is installed
  • OR libndr0-32bit-4.1.12-3 is installed
  • OR libnetapi0-4.1.12-3 is installed
  • OR libnetapi0-32bit-4.1.12-3 is installed
  • OR libpdb0-4.1.12-3 is installed
  • OR libpdb0-32bit-4.1.12-3 is installed
  • OR libregistry0-4.1.12-3 is installed
  • OR libsamba-credentials0-4.1.12-3 is installed
  • OR libsamba-credentials0-32bit-4.1.12-3 is installed
  • OR libsamba-hostconfig0-4.1.12-3 is installed
  • OR libsamba-hostconfig0-32bit-4.1.12-3 is installed
  • OR libsamba-util0-4.1.12-3 is installed
  • OR libsamba-util0-32bit-4.1.12-3 is installed
  • OR libsamdb0-4.1.12-3 is installed
  • OR libsamdb0-32bit-4.1.12-3 is installed
  • OR libsmbclient-raw0-4.1.12-3 is installed
  • OR libsmbclient-raw0-32bit-4.1.12-3 is installed
  • OR libsmbclient0-4.1.12-3 is installed
  • OR libsmbclient0-32bit-4.1.12-3 is installed
  • OR libsmbconf0-4.1.12-3 is installed
  • OR libsmbconf0-32bit-4.1.12-3 is installed
  • OR libsmbldap0-4.1.12-3 is installed
  • OR libsmbldap0-32bit-4.1.12-3 is installed
  • OR libtevent-util0-4.1.12-3 is installed
  • OR libtevent-util0-32bit-4.1.12-3 is installed
  • OR libwbclient0-4.1.12-3 is installed
  • OR libwbclient0-32bit-4.1.12-3 is installed
  • OR samba-4.1.12-3 is installed
  • OR samba-32bit-4.1.12-3 is installed
  • OR samba-client-4.1.12-3 is installed
  • OR samba-client-32bit-4.1.12-3 is installed
  • OR samba-doc-4.1.12-3 is installed
  • OR samba-libs-4.1.12-3 is installed
  • OR samba-libs-32bit-4.1.12-3 is installed
  • OR samba-winbind-4.1.12-3 is installed
  • OR samba-winbind-32bit-4.1.12-3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 12 SP1 is installed
  • AND Package Information
  • libpython2_7-1_0-2.7.9-20 is installed
  • OR libpython2_7-1_0-32bit-2.7.9-20 is installed
  • OR python-base-2.7.9-20 is installed
  • OR python-devel-2.7.9-20 is installed
  • OR python-xml-2.7.9-20 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 12 SP3 is installed
  • AND Package Information
  • cups-1.7.5-19 is installed
  • OR cups-client-1.7.5-19 is installed
  • OR cups-libs-1.7.5-19 is installed
  • OR cups-libs-32bit-1.7.5-19 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 12 SP4 is installed
  • AND Package Information
  • gnome-settings-daemon-3.20.1-50.5 is installed
  • OR gnome-settings-daemon-lang-3.20.1-50.5 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 SP1 is installed
  • AND Package Information
  • containerd-1.2.10-5.19 is installed
  • OR containerd-ctr-1.2.10-5.19 is installed
  • OR containerd-kubic-1.2.10-5.19 is installed
  • OR containerd-kubic-ctr-1.2.10-5.19 is installed
  • OR docker-19.03.5_ce-6.31 is installed
  • OR docker-kubic-19.03.5_ce-6.31 is installed
  • OR docker-kubic-bash-completion-19.03.5_ce-6.31 is installed
  • OR docker-kubic-kubeadm-criconfig-19.03.5_ce-6.31 is installed
  • OR docker-kubic-test-19.03.5_ce-6.31 is installed
  • OR docker-kubic-zsh-completion-19.03.5_ce-6.31 is installed
  • OR docker-libnetwork-kubic-0.7.0.1+gitr2877_3eb39382bfa6-4.18 is installed
  • OR docker-runc-kubic-1.0.0rc8+gitr3917_3e425f80a8c9-6.27 is installed
  • OR docker-test-19.03.5_ce-6.31 is installed
  • OR docker-zsh-completion-19.03.5_ce-6.31 is installed
  • OR golang-github-docker-libnetwork-0.7.0.1+gitr2877_3eb39382bfa6-4.18 is installed
  • OR golang-github-docker-libnetwork-kubic-0.7.0.1+gitr2877_3eb39382bfa6-4.18 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP1 is installed
  • AND Package Information
  • libpoppler-glib8-0.24.4-3 is installed
  • OR libpoppler-qt4-4-0.24.4-3 is installed
  • OR libpoppler44-0.24.4-3 is installed
  • OR poppler-tools-0.24.4-3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP1-LTSS is installed
  • AND Package Information
  • kgraft-patch-3_12_62-60_62-default-10-2 is installed
  • OR kgraft-patch-3_12_62-60_62-xen-10-2 is installed
  • OR kgraft-patch-SLE12-SP1_Update_7-10-2 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2 is installed
  • AND libmusicbrainz4-2.1.5-27 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-BCL is installed
  • AND Package Information
  • ntp-4.2.8p11-64.5 is installed
  • OR ntp-doc-4.2.8p11-64.5 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-ESPOS is installed
  • AND Package Information
  • libvirt-2.0.0-27.42 is installed
  • OR libvirt-client-2.0.0-27.42 is installed
  • OR libvirt-daemon-2.0.0-27.42 is installed
  • OR libvirt-daemon-config-network-2.0.0-27.42 is installed
  • OR libvirt-daemon-config-nwfilter-2.0.0-27.42 is installed
  • OR libvirt-daemon-driver-interface-2.0.0-27.42 is installed
  • OR libvirt-daemon-driver-libxl-2.0.0-27.42 is installed
  • OR libvirt-daemon-driver-lxc-2.0.0-27.42 is installed
  • OR libvirt-daemon-driver-network-2.0.0-27.42 is installed
  • OR libvirt-daemon-driver-nodedev-2.0.0-27.42 is installed
  • OR libvirt-daemon-driver-nwfilter-2.0.0-27.42 is installed
  • OR libvirt-daemon-driver-qemu-2.0.0-27.42 is installed
  • OR libvirt-daemon-driver-secret-2.0.0-27.42 is installed
  • OR libvirt-daemon-driver-storage-2.0.0-27.42 is installed
  • OR libvirt-daemon-hooks-2.0.0-27.42 is installed
  • OR libvirt-daemon-lxc-2.0.0-27.42 is installed
  • OR libvirt-daemon-qemu-2.0.0-27.42 is installed
  • OR libvirt-daemon-xen-2.0.0-27.42 is installed
  • OR libvirt-doc-2.0.0-27.42 is installed
  • OR libvirt-lock-sanlock-2.0.0-27.42 is installed
  • OR libvirt-nss-2.0.0-27.42 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-LTSS is installed
  • AND Package Information
  • java-1_8_0-openjdk-1.8.0.171-27.19 is installed
  • OR java-1_8_0-openjdk-demo-1.8.0.171-27.19 is installed
  • OR java-1_8_0-openjdk-devel-1.8.0.171-27.19 is installed
  • OR java-1_8_0-openjdk-headless-1.8.0.171-27.19 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3 is installed
  • AND Package Information
  • cups-pk-helper-0.2.5-5 is installed
  • OR cups-pk-helper-lang-0.2.5-5 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-BCL is installed
  • AND clamav-0.100.3-33.26 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-ESPOS is installed
  • AND Package Information
  • libvirt-3.3.0-5.40 is installed
  • OR libvirt-admin-3.3.0-5.40 is installed
  • OR libvirt-client-3.3.0-5.40 is installed
  • OR libvirt-daemon-3.3.0-5.40 is installed
  • OR libvirt-daemon-config-network-3.3.0-5.40 is installed
  • OR libvirt-daemon-config-nwfilter-3.3.0-5.40 is installed
  • OR libvirt-daemon-driver-interface-3.3.0-5.40 is installed
  • OR libvirt-daemon-driver-libxl-3.3.0-5.40 is installed
  • OR libvirt-daemon-driver-lxc-3.3.0-5.40 is installed
  • OR libvirt-daemon-driver-network-3.3.0-5.40 is installed
  • OR libvirt-daemon-driver-nodedev-3.3.0-5.40 is installed
  • OR libvirt-daemon-driver-nwfilter-3.3.0-5.40 is installed
  • OR libvirt-daemon-driver-qemu-3.3.0-5.40 is installed
  • OR libvirt-daemon-driver-secret-3.3.0-5.40 is installed
  • OR libvirt-daemon-driver-storage-3.3.0-5.40 is installed
  • OR libvirt-daemon-driver-storage-core-3.3.0-5.40 is installed
  • OR libvirt-daemon-driver-storage-disk-3.3.0-5.40 is installed
  • OR libvirt-daemon-driver-storage-iscsi-3.3.0-5.40 is installed
  • OR libvirt-daemon-driver-storage-logical-3.3.0-5.40 is installed
  • OR libvirt-daemon-driver-storage-mpath-3.3.0-5.40 is installed
  • OR libvirt-daemon-driver-storage-rbd-3.3.0-5.40 is installed
  • OR libvirt-daemon-driver-storage-scsi-3.3.0-5.40 is installed
  • OR libvirt-daemon-hooks-3.3.0-5.40 is installed
  • OR libvirt-daemon-lxc-3.3.0-5.40 is installed
  • OR libvirt-daemon-qemu-3.3.0-5.40 is installed
  • OR libvirt-daemon-xen-3.3.0-5.40 is installed
  • OR libvirt-doc-3.3.0-5.40 is installed
  • OR libvirt-libs-3.3.0-5.40 is installed
  • OR libvirt-lock-sanlock-3.3.0-5.40 is installed
  • OR libvirt-nss-3.3.0-5.40 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-LTSS is installed
  • AND Package Information
  • java-1_8_0-openjdk-1.8.0.222-27.35 is installed
  • OR java-1_8_0-openjdk-demo-1.8.0.222-27.35 is installed
  • OR java-1_8_0-openjdk-devel-1.8.0.222-27.35 is installed
  • OR java-1_8_0-openjdk-headless-1.8.0.222-27.35 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-TERADATA is installed
  • AND Package Information
  • libprocps3-3.3.9-11.14 is installed
  • OR procps-3.3.9-11.14 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4 is installed
  • AND Package Information
  • libXrandr2-1.5.0-6 is installed
  • OR libXrandr2-32bit-1.5.0-6 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server for SAP Applications 15 is installed
  • AND Package Information
  • tomcat-9.0.35-3.52 is installed
  • OR tomcat-admin-webapps-9.0.35-3.52 is installed
  • OR tomcat-el-3_0-api-9.0.35-3.52 is installed
  • OR tomcat-jsp-2_3-api-9.0.35-3.52 is installed
  • OR tomcat-lib-9.0.35-3.52 is installed
  • OR tomcat-servlet-4_0-api-9.0.35-3.52 is installed
  • OR tomcat-webapps-9.0.35-3.52 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Workstation Extension 15 is installed
  • AND Package Information
  • bluez-5.48-5.13 is installed
  • OR bluez-cups-5.48-5.13 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Workstation Extension 15 SP2 is installed
  • AND Package Information
  • xorg-x11-server-1.20.3-22.5.5 is installed
  • OR xorg-x11-server-wayland-1.20.3-22.5.5 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 7 is installed
  • AND Package Information
  • xen-4.7.6_02-43.36 is installed
  • OR xen-doc-html-4.7.6_02-43.36 is installed
  • OR xen-libs-4.7.6_02-43.36 is installed
  • OR xen-libs-32bit-4.7.6_02-43.36 is installed
  • OR xen-tools-4.7.6_02-43.36 is installed
  • OR xen-tools-domU-4.7.6_02-43.36 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 8 is installed
  • AND Package Information
  • libvirt-3.3.0-5.40 is installed
  • OR libvirt-admin-3.3.0-5.40 is installed
  • OR libvirt-client-3.3.0-5.40 is installed
  • OR libvirt-daemon-3.3.0-5.40 is installed
  • OR libvirt-daemon-config-network-3.3.0-5.40 is installed
  • OR libvirt-daemon-config-nwfilter-3.3.0-5.40 is installed
  • OR libvirt-daemon-driver-interface-3.3.0-5.40 is installed
  • OR libvirt-daemon-driver-libxl-3.3.0-5.40 is installed
  • OR libvirt-daemon-driver-lxc-3.3.0-5.40 is installed
  • OR libvirt-daemon-driver-network-3.3.0-5.40 is installed
  • OR libvirt-daemon-driver-nodedev-3.3.0-5.40 is installed
  • OR libvirt-daemon-driver-nwfilter-3.3.0-5.40 is installed
  • OR libvirt-daemon-driver-qemu-3.3.0-5.40 is installed
  • OR libvirt-daemon-driver-secret-3.3.0-5.40 is installed
  • OR libvirt-daemon-driver-storage-3.3.0-5.40 is installed
  • OR libvirt-daemon-driver-storage-core-3.3.0-5.40 is installed
  • OR libvirt-daemon-driver-storage-disk-3.3.0-5.40 is installed
  • OR libvirt-daemon-driver-storage-iscsi-3.3.0-5.40 is installed
  • OR libvirt-daemon-driver-storage-logical-3.3.0-5.40 is installed
  • OR libvirt-daemon-driver-storage-mpath-3.3.0-5.40 is installed
  • OR libvirt-daemon-driver-storage-rbd-3.3.0-5.40 is installed
  • OR libvirt-daemon-driver-storage-scsi-3.3.0-5.40 is installed
  • OR libvirt-daemon-hooks-3.3.0-5.40 is installed
  • OR libvirt-daemon-lxc-3.3.0-5.40 is installed
  • OR libvirt-daemon-qemu-3.3.0-5.40 is installed
  • OR libvirt-daemon-xen-3.3.0-5.40 is installed
  • OR libvirt-doc-3.3.0-5.40 is installed
  • OR libvirt-libs-3.3.0-5.40 is installed
  • OR libvirt-lock-sanlock-3.3.0-5.40 is installed
  • OR libvirt-nss-3.3.0-5.40 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud Crowbar 8 is installed
  • AND Package Information
  • ruby2.1-rubygem-activejob-4_2-4.2.9-3.6 is installed
  • OR rubygem-activejob-4_2-4.2.9-3.6 is installed
  • BACK