alpinelinux / docker-alpine

Official Alpine Linux Docker image. Win at minimalism!
MIT License
1.04k stars 261 forks source link

CVE-2023-6992: reported in zlib 1.2.13-r1 #373

Closed Josep-Lancharro-Indra closed 5 months ago

Josep-Lancharro-Indra commented 5 months ago

Hi, our Prisma Cloud is reporting this issue with zlib:

image

It appears to be a fix related to the issue in this commit.

Can you check that?

Thanks.

mariozelaschi commented 5 months ago

Same problem here, some details: https://nvd.nist.gov/vuln/detail/CVE-2023-6992 Just to clarify, the CVE is also detected in version 1.3.1-r0 (latest available on Alpine repo)

TheStoryEnd commented 5 months ago

CVE-2023-6992 Not related to madler/zlib: https://github.com/madler/zlib/issues/905

mariozelaschi commented 5 months ago

CVE-2023-6992 Not related to madler/zlib: madler/zlib#905

Oh! So it seems it is a false positive, thanks a lot for the link I was just going to look in closed issues for it :)