GoogleCloudPlatform / GoogleCloudPlatform/esp-v2

Zlib Memory Corruption Vulnerability (CVE-2018-25032)

Open
#696 6 comments 0 reactions 1 assignee Claimed by @TAOXUY View on GitHub
Dominant language
Go
Stars
307
Forks
185
Avg merge
14h 45m
Merged PRs (30d)
6

Description

Is it possible to up the base alpine image version as the current one has old Zlib which has reported security vulnerability CVE-2018-25032?

As per alpine security tracker this got fixed in 3.15: https://security.alpinelinux.org/vuln/CVE-2018-25032

I am currently using ESP-V2 and I can see that we have this issue in current version.
![Screenshot_20220520_152619](https://user-images.githubusercontent.com/18355446/169503980-fcb59e87-ab28-4cde-9f44-410b75b9a6c3.jpeg)

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.