Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

curl is vulnerable in the latest alpine docker image #1302

Closed
goffinf opened this issue Nov 6, 2019 · 1 comment
Closed

curl is vulnerable in the latest alpine docker image #1302

goffinf opened this issue Nov 6, 2019 · 1 comment
Labels
bug security Security related issue
Milestone

Comments

@goffinf
Copy link

goffinf commented Nov 6, 2019

Docker image version: hashicorp/consul-template:0.22.0-alpine

Show vulnerabilities in curl to 2 CVEs (see below).

Any chance of a rebuild and publish to DockerHub to pick up the latest curl version from apk ?

Resource:
curl
Description:
Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7.65.3.
Fix Version:
None
Aqua Score:
7.5 High
NVD Score (CVSS v2)
7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
NVD Reference:
https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-5481
Vendor Score (CVSS v2)
7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
Resource
curl
Description:
Heap buffer overflow in the TFTP protocol handler in cURL 7.19.4 to 7.65.3.
Fix Version:
None
Aqua Score:
7.5 High
NVD Score (CVSS v2)
7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
NVD Reference:
https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-5482
Vendor Score (CVSS v2)
7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
@eikenb eikenb added bug security Security related issue labels Nov 6, 2019
@eikenb eikenb added this to the 0.22.1 milestone Nov 8, 2019
@eikenb
Copy link
Contributor

eikenb commented Nov 8, 2019

Just released 0.22.1, which fixes this.

@eikenb eikenb closed this as completed Nov 8, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug security Security related issue
Projects
None yet
Development

No branches or pull requests

2 participants