Bug 1395092 - atomic found several CVE bugs
Summary: atomic found several CVE bugs
Keywords:
Status: CLOSED NEXTRELEASE
Alias: None
Product: Red Hat Enterprise Linux 7
Classification: Red Hat
Component: sssd-container
Version: 7.4
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: rc
: ---
Assignee: SSSD Maintainers
QA Contact: Namita Soman
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2016-11-15 06:24 UTC by Alex Jia
Modified: 2016-11-15 12:31 UTC (History)
4 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2016-11-15 08:37:26 UTC
Target Upstream Version:


Attachments (Terms of Use)

Description Alex Jia 2016-11-15 06:24:57 UTC
Description of problem:
scan complains CVE errors "RHSA-2016:2702: policycoreutils security update (Important)", "RHSA-2016:2674: libgcrypt security update (Moderate)", "RHSA-2016:2615: bind security update (Important)" in rhel7/sssd:latest(74eacb72309b).

Version-Release number of selected component (if applicable):

[root@atomic-host-001 cloud-user]# atomic host status
State: idle
Deployments:
● rhel-atomic-host:rhel-atomic-host/7/x86_64/standard
       Version: 7.3.1 (2016-11-11 03:25:08)
        Commit: 6f182afa309da8df96470ba050845629f698946e9222f67eece5a1197e296c87
        OSName: rhel-atomic-host
  GPGSignature: (unsigned)
      Unlocked: development

[root@atomic-host-001 cloud-user]# getenforce
Permissive

[root@atomic-host-001 cloud-user]# rpm -q atomic skopeo docker
atomic-1.13.8-1.el7.x86_64
skopeo-0.1.17-0.5.git1f655f3.el7.x86_64
docker-1.12.3-2.el7.x86_64

[root@atomic-host-001 cloud-user]# atomic images list
   REPOSITORY                                  TAG      IMAGE ID       CREATED            VIRTUAL SIZE   TYPE       
☠  registry.access.redhat.com/rhel7/openscap   latest   26d9de88b340   2016-10-27 09:14   360.1 MB       Docker    
☠  rhel7/sssd                                  latest   74eacb72309b   2016-10-28 21:46   357.25 MB      Docker  

How reproducible:
always

Steps to Reproduce:
1. atomic pull rhel7/sssd 
2. atomic scan --scanner openscap --scan_type cve --images


Actual results:

74eacb72309b027a31959e7f9b81259cb150ef371d8351b5146dcbbd8920af56 (rhel7/sssd:latest)

The following issues were found:

     RHSA-2016:2702: policycoreutils security update (Important)
     Severity: Important
       RHSA URL: https://rhn.redhat.com/errata/RHSA-2016-2702.html
       RHSA ID: RHSA-2016:2702-00
       Associated CVEs:
           CVE ID: CVE-2016-7545
           CVE URL: https://access.redhat.com/security/cve/CVE-2016-7545

     RHSA-2016:2674: libgcrypt security update (Moderate)
     Severity: Moderate
       RHSA URL: https://rhn.redhat.com/errata/RHSA-2016-2674.html
       RHSA ID: RHSA-2016:2674-01
       Associated CVEs:
           CVE ID: CVE-2016-6313
           CVE URL: https://access.redhat.com/security/cve/CVE-2016-6313

     RHSA-2016:2615: bind security update (Important)
     Severity: Important
       RHSA URL: https://rhn.redhat.com/errata/RHSA-2016-2615.html
       RHSA ID: RHSA-2016:2615-01
       Associated CVEs:
           CVE ID: CVE-2016-8864
           CVE URL: https://access.redhat.com/security/cve/CVE-2016-8864


Expected results:
fix CVE bugs.

Additional info:


Note You need to log in before you can comment on or make changes to this bug.