# [Critical] Photon OS Security Update ## Summary Advisory ID : PHSA-2019-1.0-0209 Type : Security Severity : {'Critical', 'Moderate', 'Important'} Issued on : 2019-02-20 Affected Versions : Photon OS 1.0 ## Details An update of {'elasticsearch', 'sqlite-autoconf', 'glibc', 'curl', 'kibana'} packages of Photon OS has been released. ## Affected Packages: ### Critical kibana - ['[CVE-2018-17245](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-17245)', '[CVE-2018-17246](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-17246)'] curl - ['[CVE-2019-3822](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-3822)', '[CVE-2019-3823](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-3823)'] ### Important sqlite-autoconf - ['[CVE-2018-20346](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-20346)'] glibc - ['[CVE-2018-19591](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-19591)'] ### Moderate elasticsearch - ['[CVE-2018-17244](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-17244)'] ## Solution Update the affected packages (tdnf update _package_) Note: For packages ['glibc'] after updating, a reboot is required for taking effect. ## Updated Packages Information elasticsearch-6.4.3-1.ph1.x86_64.rpm , sha256 : 7acab63f0643b730bf58ef53ca3c3453c337365abefe7ba927cbf1c419032f13 , size : 33M , build_date : Wed, 20 Feb 2019 13:47:08 UTC elasticsearch-6.4.3-1.ph1.src.rpm , sha256 : 363a760bdea4457f09ee29881cffac00c2da1796347aead9c92cea1963ce1048 , size : 47M , build_date : Wed, 20 Feb 2019 13:47:08 UTC sqlite-autoconf-3.26.0-1.ph1.x86_64.rpm , sha256 : cf6f5094a25b6dcd268ea3c3fcd64b67ad4bdc5973e96b68e7712eea023015da , size : 1.5M , build_date : Wed, 20 Feb 2019 13:29:26 UTC sqlite-autoconf-debuginfo-3.26.0-1.ph1.x86_64.rpm , sha256 : a999b071da0056cfdc313005dd4ee0e38e89429db69a4db4e30f86b8d9a69846 , size : 5.1M , build_date : Wed, 20 Feb 2019 13:29:26 UTC sqlite-autoconf-3.26.0-1.ph1.src.rpm , sha256 : 2fc094c197c823dca399664fe637625e05c5573180a084fdd6396c897982adb7 , size : 2.7M , build_date : Wed, 20 Feb 2019 13:29:26 UTC glibc-lang-2.22-24.ph1.x86_64.rpm , sha256 : 6f483de001c539044ccaf5d8e5d2785ff366116abd688503dadd05bf66f3f4b6 , size : 1.4M , build_date : Wed, 20 Feb 2019 13:22:47 UTC glibc-2.22-24.ph1.x86_64.rpm , sha256 : 98b174c99b724211aa39a5959df5f00e4f85b942dfd516cb9023c4f8ade5d6a9 , size : 19M , build_date : Wed, 20 Feb 2019 13:22:47 UTC glibc-devel-2.22-24.ph1.x86_64.rpm , sha256 : 7279cb12478513c0d129e2f9ff1397bcc01b4f703b83c57436b8194446bd6c57 , size : 12M , build_date : Wed, 20 Feb 2019 13:22:47 UTC glibc-2.22-24.ph1.src.rpm , sha256 : acfa6f0be68ed4fee0c65a51236470d595b20b6349d1f98d27344afcdbdfef7e , size : 13M , build_date : Wed, 20 Feb 2019 13:22:47 UTC curl-debuginfo-7.59.0-6.ph1.x86_64.rpm , sha256 : e4cded56b120fbf3bebc11f911979f3ef2b24a8f85d6258deec931e24aca892a , size : 35K , build_date : Wed, 20 Feb 2019 13:31:59 UTC curl-7.59.0-6.ph1.x86_64.rpm , sha256 : 02ba6d6cc53063c21f2e7312c57dde9ce10ba7c2112c83e65462b02e4949dd3b , size : 1.1M , build_date : Wed, 20 Feb 2019 13:31:59 UTC curl-7.59.0-6.ph1.src.rpm , sha256 : 6f0559d8ad962c49a865ed7896b8c4ffb1944f9ccd4f6899f129fb28b172e92a , size : 3.8M , build_date : Wed, 20 Feb 2019 13:31:59 UTC kibana-6.4.3-1.ph1.x86_64.rpm , sha256 : 43f7a5b1be41103432c3841d3b164e41d45fb51264a503a37f956c058ac8167d , size : 59M , build_date : Wed, 20 Feb 2019 15:20:01 UTC kibana-6.4.3-1.ph1.src.rpm , sha256 : 1fedcba722051c62f37145b8fdb2e063c6f0ae59ef3a92dbfd38a29d08dff4d5 , size : 799M , build_date : Wed, 20 Feb 2019 15:20:01 UTC