Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fix code scanning alert - libexpat: Integer Overflow or Wraparound #1810

Closed
35 tasks
SanjayVas opened this issue Sep 17, 2024 · 3 comments · Fixed by #1819
Closed
35 tasks

Fix code scanning alert - libexpat: Integer Overflow or Wraparound #1810

SanjayVas opened this issue Sep 17, 2024 · 3 comments · Fixed by #1819

Comments

@SanjayVas
Copy link
Member

SanjayVas commented Sep 17, 2024

CVE-2024-45491

Tracking issue for:

@SanjayVas
Copy link
Member Author

Not yet fixed in upstream Debian Bookworm. See https://security-tracker.debian.org/tracker/CVE-2024-45491

@SanjayVas
Copy link
Member Author

SanjayVas commented Sep 18, 2024

Looks like bookworm (security) has the fixed version now, which means it should be picked up by upstream distroless soon.

@SanjayVas
Copy link
Member Author

Appears to be fixed in latest gcr.io/distroless/java17-debian12:nonroot (sha256:2db4acff2603088acaf67dac414462c9fcc3e2cc3ff9a642d5af9c7cff2b5fe9)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
1 participant