Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Zlib CVE (CVE-2022-37434) #276

Closed
mehta-ankit opened this issue Aug 24, 2022 · 2 comments
Closed

Zlib CVE (CVE-2022-37434) #276

mehta-ankit opened this issue Aug 24, 2022 · 2 comments

Comments

@mehta-ankit
Copy link

mehta-ankit commented Aug 24, 2022

Zlib has a CVE on it: https://nvd.nist.gov/vuln/detail/CVE-2022-37434
Alpine 3:16 does pull in the vulnerable version.

Zlib has a fix: madler/zlib@1eb7682 but has not made a new release: madler/zlib#686. Once released we should update the version of zlib on alpine.

@mehta-ankit
Copy link
Author

Looks like apk package has been updated that gets installed on Alpine: https://git.alpinelinux.org/aports/commit/?id=3811d63f756f2a6786a29208975de6c64b2d79f3

@Neustradamus
Copy link

@madler has done the new build, the 1.2.13 has been released with the CVE-2022-37434 fix.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants