Red Hat Updates
2518Warning Date
Severity Level
Warning Number
Target Sector
15 March, 2020
● High
2020-1020
All
Description:
Red Hat has released security updates to address vulnerabilities in the following products:
- qemu-kvm-rhev
- Red Hat OpenStack - Extended Update Support 13 for RHEL 7.6 x86_64
- qemu-kvm
- Red Hat Enterprise Linux Server 6 x86_64
- Red Hat Enterprise Linux Server 6 i386
- Red Hat Enterprise Linux Workstation 6 x86_64
- Red Hat Enterprise Linux Workstation 6 i386
- Red Hat Enterprise Linux Desktop 6 x86_64
- Red Hat Enterprise Linux Desktop 6 i386
- Red Hat Enterprise Linux for Power, big endian 6 ppc64
- Red Hat Enterprise Linux for Scientific Computing 6 x86_64
- OpenShift Container Platform 4.2.22 skopeo
- Red Hat OpenShift Container Platform 4.2 for RHEL 8 x86_64
- Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.2 for RHEL 8 s390x
- OpenShift Container Platform 4.2.22 runc
- Red Hat OpenShift Container Platform 4.2 for RHEL 8 x86_64
- Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.2 for RHEL 8 s390x
- chromium-browser
- Red Hat Enterprise Linux Server 6 x86_64
- Red Hat Enterprise Linux Server 6 i386
- Red Hat Enterprise Linux Workstation 6 x86_64
- Red Hat Enterprise Linux Workstation 6 i386
- Red Hat Enterprise Linux Desktop 6 x86_64
- Red Hat Enterprise Linux Desktop 6 i386
- Red Hat Enterprise Linux for Scientific Computing 6 x86_64
- OpenShift Container Platform 4.3.5 podman
- Red Hat OpenShift Container Platform 4.3 for RHEL 8 x86_64
- OpenShift Container Platform 4.3.5 skopeo
- Red Hat OpenShift Container Platform 4.3 for RHEL 8 x86_64
- OpenShift Container Platform 4.3.5
- Red Hat OpenShift Container Platform 4.3 for RHEL 8 x86_64
- Red Hat OpenShift Container Platform 4.3 for RHEL 7 x86_64
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Buffer overflow
- Execute arbitrary code
- Escalation of privilege
Best practice and Recommendations:
The CERT team encourages users to review Red Hat security advisory and apply the necessary updates:
- https://access.redhat.com/errata/RHSA-2020:0773
- https://access.redhat.com/errata/RHSA-2020:0775
- https://access.redhat.com/errata/RHSA-2020:0689
- https://access.redhat.com/errata/RHSA-2020:0688
- https://access.redhat.com/errata/RHSA-2020:0779
- https://access.redhat.com/errata/RHSA-2020:0680
- https://access.redhat.com/errata/RHSA-2020:0679
- https://access.redhat.com/errata/RHSA-2020:0681