namshi / docker-smtp

SMTP docker container
MIT License
548 stars 198 forks source link

CVE-2019-10149 #54

Closed issa-tseng closed 5 years ago

issa-tseng commented 5 years ago

someone will have to rebuild and republish this package bundling 4.89-2+deb9u4 or higher.

issa-tseng commented 5 years ago

here is a link to the advisory: https://www.openwall.com/lists/oss-security/2019/06/05/4 here is a link to the debian security tracking page: https://security-tracker.debian.org/tracker/CVE-2019-10149

issa-tseng commented 5 years ago

(right now the image bundles deb9u3 which they show as vulnerable.)

issa-tseng commented 5 years ago

since nothing has happened here, i have built an updated image (with no changes from master) and pushed it to docker hub here.

alexanderadam commented 5 years ago

Thank you.

PS: IMHO the correct link would be this.

oba11 commented 5 years ago

Apologies everyone, this has been resolved and a new image pushed to docker hub.