google / log4jscanner

A log4j vulnerability filesystem scanner and Go package for analyzing JAR files.
Apache License 2.0
1.57k stars 120 forks source link

scanner fails if /tmp is on a different filesystem than the filesystem being scanned on linux #18

Closed cmedianu closed 2 years ago

cmedianu commented 2 years ago

log4jscanner.go:119: Error: scanning oracle/product/19.0.0.0/dbhome_1/suptools/tfa/release/tfa_home/jlib/tfa.war: overwriting product/19.0.0.0/dbhome_1/suptools/tfa/release/tfa_home/jlib/tfa.war: rename /tmp/1487074654 oracle/product/19.0.0.0/dbhome_1/suptools/tfa/release/tfa_home/jlib/tfa.war: invalid cross-device link

ericchiang commented 2 years ago

Thanks! I'll try to fix this when sending a PR for #13

cmedianu commented 2 years ago

@ericchiang thanks for fixing it! When will it be released as linux binary?