- Issued:
- 2016-02-23
- Updated:
- 2016-02-23
RHBA-2016:0291 - Bug Fix Advisory
Synopsis
Red Hat OpenShift Enterprise 3.1 security image update
Type/Severity
Bug Fix Advisory
Topic
Updated images that include a security fix are now available for Red Hat OpenShift Enterprise 3.1.
Description
OpenShift Enterprise by Red Hat is the company's cloud computing Platform-as-a-Service (PaaS) solution designed for on-premise or private cloud deployments.
The images in this update include the glibc fix for CVE-2015-7547. For more details, see https://access.redhat.com/security/vulnerabilities/2168451.
This update includes the following images:
openshift3/image-inspector:1.0.0-6
openshift3/jenkins-1-rhel7:1.625-21
openshift3/logging-auth-proxy:3.1.1-6
openshift3/logging-deployment:3.1.1-6
openshift3/logging-elasticsearch:3.1.1-6
openshift3/logging-fluentd:3.1.1-6
openshift3/logging-kibana:3.1.1-6
openshift3/metrics-cassandra:3.1.1-6
openshift3/metrics-deployer:3.1.1-4
openshift3/metrics-hawkular-metrics:3.1.1-5
openshift3/metrics-heapster:3.1.1-4
openshift3/mongodb-24-rhel7:2.4-19
openshift3/mysql-55-rhel7:5.5-20
openshift3/nodejs-010-rhel7:0.10-21
openshift3/node:v3.1.1.6-9
openshift3/openvswitch:v3.1.1.6-5
openshift3/ose-deployer:v3.1.1.6-10
openshift3/ose-docker-builder:v3.1.1.6-9
openshift3/ose-docker-registry:v3.1.1.6-5
openshift3/ose-f5-router:v3.1.1.6-10
openshift3/ose-haproxy-router:v3.1.1.6-5
openshift3/ose-keepalived-ipfailover:v3.1.1.6-5
openshift3/ose-pod:v3.1.1.6-5
openshift3/ose-recycler:v3.1.1.6-5
openshift3/ose-sti-builder:v3.1.1.6-9
openshift3/ose:v3.1.1.6-10
openshift3/perl-516-rhel7:5.16-21
openshift3/php-55-rhel7:5.5-21
openshift3/postgresql-92-rhel7:9.2-20
openshift3/python-33-rhel7:3.3-21
openshift3/ruby-20-rhel7:2.0-21
All OpenShift Enterprise 3 users are advised to upgrade to these updated images.
Solution
Before applying this update, make sure all previously released errata relevant to your system have been applied.
The Red Hat Enterprise Linux container images provided by this update can be downloaded from the Red Hat Container Registry at registry.access.redhat.com using the "docker pull" command. Dockerfiles and scripts should be amended either to refer to this new image specifically, or to the latest image generally.
Affected Products
- Red Hat OpenShift Container Platform 3.1 x86_64
Fixes
- BZ - 1309879 - Update images for CVE 2015-7547
CVEs
(none)
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.