ubuntu-docker-images team mailing list archive
-
ubuntu-docker-images team
-
Mailing list archive
-
Message #00444
Re: squid contains outdated Ubuntu packages
On Thursday, December 08 2022, security-team-toolbox-bot@xxxxxxxxxxxxx wrote:
> A scan of this rock shows that it was built with packages from the Ubuntu
> archive that have since received security updates. The following lists new
> USNs for affected binary packages in each rock revision:
>
> Revision r4e7cfb7c3799 (arm64; channels: 4.10-20.04_beta, 4.10-20.04_edge)
> * libasn1-8-heimdal: 5766-1
> * libgssapi3-heimdal: 5766-1
> * libhcrypto4-heimdal: 5766-1
> * libheimbase1-heimdal: 5766-1
> * libheimntlm0-heimdal: 5766-1
> * libhx509-5-heimdal: 5766-1
> * libkrb5-26-heimdal: 5766-1
> * libroken18-heimdal: 5766-1
> * libwind0-heimdal: 5766-1
>
> Revision r81a41ad55ac5 (ppc64le; channels: 4.10-20.04_beta, 4.10-20.04_edge)
> * libasn1-8-heimdal: 5766-1
> * libgssapi3-heimdal: 5766-1
> * libhcrypto4-heimdal: 5766-1
> * libheimbase1-heimdal: 5766-1
> * libheimntlm0-heimdal: 5766-1
> * libhx509-5-heimdal: 5766-1
> * libkrb5-26-heimdal: 5766-1
> * libroken18-heimdal: 5766-1
> * libwind0-heimdal: 5766-1
>
> Revision rd54ac2c906ef (s390x; channels: 4.10-20.04_beta, 4.10-20.04_edge)
> * libasn1-8-heimdal: 5766-1
> * libgssapi3-heimdal: 5766-1
> * libhcrypto4-heimdal: 5766-1
> * libheimbase1-heimdal: 5766-1
> * libheimntlm0-heimdal: 5766-1
> * libhx509-5-heimdal: 5766-1
> * libkrb5-26-heimdal: 5766-1
> * libroken18-heimdal: 5766-1
> * libwind0-heimdal: 5766-1
>
> Revision re25a220a6a45 (amd64; channels: 4.10-20.04_beta, 4.10-20.04_edge)
> * libasn1-8-heimdal: 5766-1
> * libgssapi3-heimdal: 5766-1
> * libhcrypto4-heimdal: 5766-1
> * libheimbase1-heimdal: 5766-1
> * libheimntlm0-heimdal: 5766-1
> * libhx509-5-heimdal: 5766-1
> * libkrb5-26-heimdal: 5766-1
> * libroken18-heimdal: 5766-1
> * libwind0-heimdal: 5766-1
>
> Simply rebuilding the rock will pull in the new security updates and
> resolve this. If your rock also contains vendored code, now might be a
> good time to review it for any needed updates.
>
> Thank you for your rock and for attending to this matter.
>
> References:
> * https://ubuntu.com/security/notices/USN-5766-1/
Rebuilt and retagged.
--
Sergio
GPG key ID: E92F D0B3 6B14 F1F4 D8E0 EB2F 106D A1C8 C3CB BF14
References