ubuntu-docker-images team mailing list archive
-
ubuntu-docker-images team
-
Mailing list archive
-
Message #00292
Re: postgres contains outdated Ubuntu packages
These images were re-built and re-tagged.
On Fri, Aug 5, 2022 at 2:15 AM <security-team-toolbox-bot@xxxxxxxxxxxxx>
wrote:
> A scan of this rock shows that it was built with packages from the Ubuntu
> archive that have since received security updates. The following lists new
> USNs for affected binary packages in each rock revision:
>
> Revision r0589ab4da16b (arm64; channels: latest, edge, 14-22.04_beta,
> 14-22.04_edge)
> * libgnutls30: 5550-1
>
> Revision r09bcb9f147cb (ppc64le; channels: latest, edge, 14-22.04_beta,
> 14-22.04_edge)
> * libgnutls30: 5550-1
>
> Revision r09e123c94728 (s390x; channels: 12-20.04_beta, 12-20.04_edge)
> * libgnutls30: 5550-1
> * libxml2: 5548-1
>
> Revision r32b063810907 (amd64; channels: latest, edge, 14-22.04_beta,
> 14-22.04_edge)
> * libgnutls30: 5550-1
>
> Revision r595bcdeb9923 (ppc64le; channels: 12-20.04_beta, 12-20.04_edge)
> * libgnutls30: 5550-1
> * libxml2: 5548-1
>
> Revision r67a4bb83f253 (s390x; channels: latest, edge, 14-22.04_beta,
> 14-22.04_edge)
> * libgnutls30: 5550-1
>
> Revision r84f653abc76a (amd64; channels: 12-20.04_beta, 12-20.04_edge)
> * libgnutls30: 5550-1
> * libxml2: 5548-1
>
> Revision reccd6556e61d (arm64; channels: 12-20.04_beta, 12-20.04_edge)
> * libgnutls30: 5550-1
> * libxml2: 5548-1
>
> Simply rebuilding the rock will pull in the new security updates and
> resolve this. If your rock also contains vendored code, now might be a
> good time to review it for any needed updates.
>
> Thank you for your rock and for attending to this matter.
>
> References:
> * https://ubuntu.com/security/notices/USN-5548-1/
> * https://ubuntu.com/security/notices/USN-5550-1/
>
References