Skip to content
This repository has been archived by the owner on Dec 4, 2024. It is now read-only.

Update base container to resolve CVE-2017-12424 #506

Merged
merged 2 commits into from
Oct 13, 2017
Merged

Conversation

keith-mcclellan
Copy link
Contributor

Updated base container to debian:buster to resolve this attack vector.
https://security-tracker.debian.org/tracker/CVE-2017-12424

keith-mcclellan added 2 commits October 13, 2017 17:31
@keith-mcclellan
Copy link
Contributor Author

This is required by a gov't user - thanks!!

Copy link
Contributor

@justinrlee justinrlee left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good to me - pretty straightforward changes.

@justinrlee justinrlee merged commit b2a7c7f into master Oct 13, 2017
manriquecms pushed a commit to manriquecms/marathon-lb that referenced this pull request Feb 7, 2018
* Update base container to resolve CVE-2017-12424

Updated base container to debian:buster to resolve this attack vector.
https://security-tracker.debian.org/tracker/CVE-2017-12424

* delete unnecessary swp file
manriquecms added a commit to Stratio/marathon-lb-sec that referenced this pull request Feb 8, 2018
* Change README.md (d2iq-archive#487)

Proposed change to README.md to warn users about use of zdd.py on a production environment.

* Add container syslogd support and fix 'Waiting for Pids' race condition (d2iq-archive#505)

* Add additional debug logs in reload
* Adding syslog support
* Make syslogd and retry reload configurable
* Update documentation
* Make infinite retries optional, run syslogd with runsvdir

* Update base container to resolve CVE-2017-12424 (d2iq-archive#506)

* Update base container to resolve CVE-2017-12424

Updated base container to debian:buster to resolve this attack vector.
https://security-tracker.debian.org/tracker/CVE-2017-12424

* delete unnecessary swp file

* Fix grammar in tini section of README.md (d2iq-archive#442)

* exclude bad apps from generated config (d2iq-archive#481)

exclude bad apps from generated config

* Fix reconnect logging and timing depending on error type (d2iq-archive#523)

* Fix reconnect logging and timing depending on error type

* cleanup flake8 errors

* add missing build-essential

* start at most one thread and close connection when reconnecting

* Filter events on server side, in order to decrease load on Marathon (d2iq-archive#541)

* Filter events on server side, in order to decrease load on Marathon
* Use lightweight Marathon events.

* Update official Marathon-LB version to 1.11.3

* Fix error with bash run script, percentage symbol was not escaped
@justinrlee justinrlee deleted the security-fixes branch April 27, 2018 13:58
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants