--------------------------------------------------------------------------------
Fedora EPEL Update Notification
FEDORA-EPEL-2025-39c166b09c
2025-12-31 00:24:47.737578+00:00
--------------------------------------------------------------------------------

Name        : podman-tui
Product     : Fedora EPEL 10.2
Version     : 1.10.0
Release     : 1.el10_2
URL         : https://github.com/containers/podman-tui
Summary     : Podman Terminal User Interface
Description :

podman-tui is a terminal user interface for Podman v4 and v5.
podman-tui is using podman.socket service to communicate with podman environment
and SSH to connect to remote podman machines.

--------------------------------------------------------------------------------
Update Information:

release 1.10.0
--------------------------------------------------------------------------------
ChangeLog:

* Mon Dec 22 2025 Navid Yaghoobi <[email protected]> - 1.10.0-1
- Release 1.10.0
* Fri Oct 10 2025 Alejandro Sáez <[email protected]> - 1.9.0-2
- rebuild
* Sat Oct  4 2025 Navid Yaghoobi <[email protected]> - 1.9.0-1
- Release v1.9.0
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2398307 - CVE-2025-47910 podman-tui: CrossOriginProtection bypass 
in net/http [epel-10]
        https://bugzilla.redhat.com/show_bug.cgi?id=2398307
  [ 2 ] Bug #2398943 - CVE-2025-47906 podman-tui: Unexpected paths returned 
from LookPath in os/exec [epel-10]
        https://bugzilla.redhat.com/show_bug.cgi?id=2398943
  [ 3 ] Bug #2407492 - CVE-2025-58189 podman-tui: go crypto/tls ALPN 
negotiation error contains attacker controlled information [epel-10]
        https://bugzilla.redhat.com/show_bug.cgi?id=2407492
  [ 4 ] Bug #2408532 - CVE-2025-61725 podman-tui: Excessive CPU consumption in 
ParseAddress in net/mail [epel-10]
        https://bugzilla.redhat.com/show_bug.cgi?id=2408532
  [ 5 ] Bug #2408944 - CVE-2025-61723 podman-tui: Quadratic complexity when 
parsing some invalid inputs in encoding/pem [epel-10]
        https://bugzilla.redhat.com/show_bug.cgi?id=2408944
  [ 6 ] Bug #2409886 - CVE-2025-58185 podman-tui: Parsing DER payload can cause 
memory exhaustion in encoding/asn1 [epel-10]
        https://bugzilla.redhat.com/show_bug.cgi?id=2409886
  [ 7 ] Bug #2410826 - CVE-2025-58188 podman-tui: Panic when validating 
certificates with DSA public keys in crypto/x509 [epel-10]
        https://bugzilla.redhat.com/show_bug.cgi?id=2410826
  [ 8 ] Bug #2412492 - CVE-2025-58183 podman-tui: Unbounded allocation when 
parsing GNU sparse map [epel-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2412492
  [ 9 ] Bug #2420558 - CVE-2025-47913 podman-tui: 
golang.org/x/crypto/ssh/agent: SSH client panic due to unexpected 
SSH_AGENT_SUCCESS [epel-10]
        https://bugzilla.redhat.com/show_bug.cgi?id=2420558
--------------------------------------------------------------------------------

This update can be installed with the "yum" update programs.  Use
su -c 'yum update podman-tui' at the command line.
For more information, refer to "YUM", available at
https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7\
/html/System_Administrators_Guide/ch-yum.html

All packages are signed with the Fedora EPEL GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------

-- 
_______________________________________________
epel-package-announce mailing list -- 
[email protected]
To unsubscribe send an email to 
[email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/[email protected]
Do not reply to spam, report it: 
https://pagure.io/fedora-infrastructure/new_issue

Reply via email to