Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Use newer zlib than shipped in AL2 #110

Merged
merged 1 commit into from
Aug 31, 2023

Conversation

GrahamCampbell
Copy link
Contributor

Just like in bref 1.x, because Amazon have not updated their version in a long time, and it has security issues.

@mnapoli
Copy link
Member

mnapoli commented Aug 21, 2023

Do you have more details on the version difference and which security issues are present in Lambda? (it's just that adding a new extra step to the compilation is something I'd rather avoid if possible)

@GrahamCampbell
Copy link
Contributor Author

CVE-2022-37434 is a vulnerability that's reachable using user-land curl bindings in PHP.

@GrahamCampbell
Copy link
Contributor Author

I went through the AL2 release notes, and no new zlib versions are listed as published any time since this vulnerability to date.

@mnapoli
Copy link
Member

mnapoli commented Aug 31, 2023

Thanks, I double-checked inside Lambda (not just the Docker image), and it's indeed the same version there too, they haven't patched the runtime. I don't want to add more to the layers but since it involves security issues let's do it.

@mnapoli mnapoli merged commit 0e16c91 into brefphp:main Aug 31, 2023
5 checks passed
@GrahamCampbell GrahamCampbell deleted the use-newer-zlib branch August 31, 2023 12:15
@mnapoli mnapoli mentioned this pull request Aug 31, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants