- Issued:
- 2019-04-17
- Updated:
- 2019-04-17
RHBA-2019:0769 - Bug Fix Advisory
Synopsis
.NET Core on Red Hat Enterprise Linux Container Image Updates
Type/Severity
Bug Fix Advisory
Topic
.NET Core has been updated the new security release.
The new versions are as such:
2.1.10 Runtime
2.1.506 SDK
2.2.4 Runtime
2.2.106 SDK
The 1.0, 1.1, 2.1 Runtime and SDK images, and the 2.2 Runtime and SDK images have also had the following CVEs addressed:
CVE-2019-3855
CVE-2019-3856
CVE-2019-3857
CVE-2019-3863
CVE-2019-9636
The 2.1 and 2.2 Jenkins Slave images had also had the following CVEs addressed:
CVE-2018-5407
CVE-2019-3855
CVE-2019-3856
CVE-2019-3857
CVE-2019-3863
CVE-2017-15137
CVE-2017-15138
Description
The .NET Core on Red Hat Enterprise Linux container images have been updated to address security advisory: RHSA-2019:0710.
Users of .NET Core on Red Hat Enterprise Linux container images are advised to upgrade to these updated images, which contain backported patches to correct these security issues, fix these bugs, and add these enhancements. Users of these images are also encouraged to rebuild all container images that depend on these images.
You can find images updated by this advisory in Red Hat Container Catalog [1].
.NET Core has been updated with the new security release. The new versions are as such:
2.1.10 Runtime
2.1.506 SDK
2.2.4 Runtime
2.2.106 SDK
The 1.0, 1.1, 2.1 Runtime and SDK images, and the 2.2 Runtime and SDK images have also had the following CVEs addressed:
CVE-2019-3855
CVE-2019-3856
CVE-2019-3857
CVE-2019-3863
CVE-2019-9636
The 2.1 and 2.2 Jenkins Slave images had also had the following CVEs addressed:
CVE-2018-5407
CVE-2019-3855
CVE-2019-3856
CVE-2019-3857
CVE-2019-3863
CVE-2017-15137
CVE-2017-15138
Solution
The .NET Core on Red Hat Enterprise Linux container images provided by this update can be downloaded from the Red Hat Container Registry at registry.access.redhat.com. Installation instructions for your platform are available at Red Hat Container Catalog [2].
Dockerfiles and scripts should be amended either to refer to this new image specifically or to the latest image generally.
Affected Products
- dotNET on RHEL (for RHEL Server) 1 x86_64
Fixes
- BZ - 1688543 - CVE-2019-9636 python: Information Disclosure due to urlsplit improper NFKC normalization
CVEs
(none)
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.