- Issued:
- 2019-05-20
- Updated:
- 2019-05-20
RHBA-2019:1246 - Bug Fix Advisory
Synopsis
updated DevTools container images
Type/Severity
Bug Fix Advisory
Topic
Updated Red Hat Developer Tools container images are now available in the Red Hat Container Registry.
Description
Red Hat Developer Tools container images are based on the corresponding compiler toolset and the rhel7:7.6 base image.
The following container images have been updated to provide a fix for CVE-2019-9636:
devtools/go-toolset-1.11-rhel7:1.11.5-3
devtools/llvm-toolset-7.0-rhel7:7.0.1-10
devtools/rust-toolset-1.31-rhel7:1.31.1-5
To pull a devtools/<image_name> image, run the following command as root:
podman pull registry.access.redhat.com/devtools/<image_name>
For details regarding usage of the container images, see the documentation linked from the References section.
All users of the Red Hat Developer Tools container images are advised to pull these updated images from the Red Hat Container Registry.
Solution
The container images provided by this update can be downloaded from the Red Hat Container Registry at registry.access.redhat.com using the "podman pull" command.
Affected Products
- Red Hat Developer Tools (for RHEL Server) 1 x86_64
- Red Hat Developer Tools (for RHEL Server for System Z) 1 s390x
- Red Hat Developer Tools (for RHEL Server for IBM Power LE) 1 ppc64le
Fixes
- BZ - 1688543 - CVE-2019-9636 python: Information Disclosure due to urlsplit improper NFKC normalization
CVEs
References
- https://access.redhat.com/documentation/en-us/red_hat_developer_tools/2019.1/html/using_go_toolset/chap-image
- https://access.redhat.com/documentation/en-us/red_hat_developer_tools/2019.1/html/using_rust_toolset/chap-image
- https://access.redhat.com/documentation/en-us/red_hat_developer_tools/2019.1/html/using_clang_and_llvm_toolset/chap-image
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.