GO-2023-1942
Podman Symlink Vulnerability in github.com/containers/libpod
Quick fix
GO-2023-1942 — github.com/containers/libpod: upgrade to the fixed version with the command below.
go get github.com/containers/libpod@v1.6.0Details
Podman Symlink Vulnerability in github.com/containers/libpod
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 1.6.0go get github.com/containers/libpod@v1.6.00No fixed version published yet for github.com/containers/podman (go modules). Pin to a known-safe version or switch to an alternative.
0No fixed version published yet for github.com/containers/podman/v2 (go modules). Pin to a known-safe version or switch to an alternative.
0No fixed version published yet for github.com/containers/podman/v3 (go modules). Pin to a known-safe version or switch to an alternative.
0No fixed version published yet for github.com/containers/podman/v4 (go modules). Pin to a known-safe version or switch to an alternative.
References
- https://github.com/advisories/GHSA-r34v-gqmw-qvgj[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2019-18466[ADVISORY]
- https://github.com/containers/libpod/commit/5c09c4d2947a759724f9d5aef6bac04317e03f7e[FIX]
- https://github.com/containers/libpod/issues/3829[REPORT]
- https://access.redhat.com/errata/RHSA-2019:4269[WEB]
- https://bugzilla.redhat.com/show_bug.cgi?id=1744588[WEB]
- https://github.com/containers/libpod/compare/v1.5.1...v1.6.0[WEB]