ubuntu-docker-images team mailing list archive
-
ubuntu-docker-images team
-
Mailing list archive
-
Message #00260
mysql contains outdated Ubuntu packages
-
To:
rocks@xxxxxxxxxxxxx, sergio.durigan@xxxxxxxxxxxxx, balbir.thomas@xxxxxxxxxxxxx, athos.ribeiro@xxxxxxxxxxxxx, paulo.machado@xxxxxxxxxxxxx, jose.masson@xxxxxxxxxxxxx, leon.mintz@xxxxxxxxxxxxx, ryan.barry@xxxxxxxxxxxxx, simon.aronsson@xxxxxxxxxxxxx, ubuntu-docker-images@xxxxxxxxxxxxxxxxxxx
-
From:
security-team-toolbox-bot@xxxxxxxxxxxxx
-
Date:
Wed, 6 Jul 2022 05:15:27 +0000 (UTC)
A scan of this rock shows that it was built with packages from the Ubuntu
archive that have since received security updates. The following lists new
USNs for affected binary packages in each rock revision:
Revision r0ad9f044b29e (amd64; channels: 8.0-20.04_edge, 8.0-20.04_beta)
* gpgv: 5503-1
* libssl1.1: 5502-1
* openssl: 5502-1
Revision r13029db19493 (arm64; channels: 8.0-22.04_edge, edge, 8.0-22.04_beta, latest)
* gpgv: 5503-1
* libssl3: 5502-1
* openssl: 5502-1
Revision r2a10e392f30e (s390x; channels: 8.0-21.10_beta, 8.0-21.10_edge)
* gpgv: 5503-1
* libssl1.1: 5502-1
* openssl: 5502-1
Revision r4202f2f14ab2 (s390x; channels: 8.0-22.04_edge, edge, 8.0-22.04_beta, latest)
* gpgv: 5503-1
* libssl3: 5502-1
* openssl: 5502-1
Revision r45249dc5e5a6 (ppc64le; channels: 8.0-20.04_edge, 8.0-20.04_beta)
* gpgv: 5503-1
* libssl1.1: 5502-1
* openssl: 5502-1
Revision r5ddb4de84621 (amd64; channels: 8.0-21.10_beta, 8.0-21.10_edge)
* gpgv: 5503-1
* libssl1.1: 5502-1
* openssl: 5502-1
Revision r8f7db3210c5e (arm64; channels: 8.0-20.04_edge, 8.0-20.04_beta)
* gpgv: 5503-1
* libssl1.1: 5502-1
* openssl: 5502-1
Revision ra621b8948243 (ppc64le; channels: 8.0-22.04_edge, edge, 8.0-22.04_beta, latest)
* gpgv: 5503-1
* libssl3: 5502-1
* openssl: 5502-1
Revision rc88327a9d5a4 (ppc64le; channels: 8.0-21.10_beta, 8.0-21.10_edge)
* gpgv: 5503-1
* libssl1.1: 5502-1
* openssl: 5502-1
Revision rca164666bc58 (arm64; channels: 8.0-21.10_beta, 8.0-21.10_edge)
* gpgv: 5503-1
* libssl1.1: 5502-1
* openssl: 5502-1
Revision rec233e22be22 (amd64; channels: 8.0-22.04_edge, edge, 8.0-22.04_beta, latest)
* gpgv: 5503-1
* libssl3: 5502-1
* openssl: 5502-1
Revision rfaecf18a8113 (s390x; channels: 8.0-20.04_edge, 8.0-20.04_beta)
* gpgv: 5503-1
* libssl1.1: 5502-1
* openssl: 5502-1
Simply rebuilding the rock will pull in the new security updates and
resolve this. If your rock also contains vendored code, now might be a
good time to review it for any needed updates.
Thank you for your rock and for attending to this matter.
References:
* https://ubuntu.com/security/notices/USN-5502-1/
* https://ubuntu.com/security/notices/USN-5503-1/
Follow ups