Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.bugs.dist > #1197831

Bug#1071276: Is 1:1.2.13.dfsg-1 affected by CVE-2023-45853, and if it is, will 1:1.3.dfsg-3.1 be backported to bookworm?

From Salvatore Bonaccorso <carnil@debian.org>
Newsgroups linux.debian.bugs.dist
Subject Bug#1071276: Is 1:1.2.13.dfsg-1 affected by CVE-2023-45853, and if it is, will 1:1.3.dfsg-3.1 be backported to bookworm?
Date 2024-05-18 11:10 +0200
Message-ID <IFoeJ-e9Ve-1@gated-at.bofh.it> (permalink)
References <IF74d-dYFh-11@gated-at.bofh.it> <IF8tj-dZDe-3@gated-at.bofh.it> <IFc3T-e1Q3-1@gated-at.bofh.it> <IF74d-dYFh-11@gated-at.bofh.it> <IFc3T-e1Q3-1@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


Hi John,

On Fri, May 17, 2024 at 04:01:56PM -0400, John Waffle wrote:
> This report came from a free tool, trivy, I filed a Github discussion about
> it here: https://github.com/aquasecurity/trivy/discussions/6722

Thanks a lot for bringing that upstream.

So to add some additional datapoint: The issue araises here by maybe
thinking zlib refers to the binary package produced. It is correct,
for the binary package zlib then indeed you would not be vulnerable. 

Let me as well elaborate on the "ingored". This comes as the binary
packages built from the *vulnerable* source, there is no point to
force an update in bookworm and older.

I hope this all get a better picture now on the CVE. If you still have
questions feel free to ask.

Regards,
Salvatore

Back to linux.debian.bugs.dist | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

Bug#1071276: Is 1:1.2.13.dfsg-1 affected by CVE-2023-45853, and if it is, will 1:1.3.dfsg-3.1 be backported to bookworm? John Waffle <jwaffe75@gmail.com> - 2024-05-17 16:50 +0200
  Bug#1071276: Is 1:1.2.13.dfsg-1 affected by CVE-2023-45853, and if it is, will 1:1.3.dfsg-3.1 be backported to bookworm? Mark Brown <broonie@debian.org> - 2024-05-17 17:00 +0200
    Bug#1071276: Is 1:1.2.13.dfsg-1 affected by CVE-2023-45853, and if it is, will 1:1.3.dfsg-3.1 be backported to bookworm? John Waffle <jwaffe75@gmail.com> - 2024-05-17 17:10 +0200
      Bug#1071276: Is 1:1.2.13.dfsg-1 affected by CVE-2023-45853, and if it is, will 1:1.3.dfsg-3.1 be backported to bookworm? Mark Brown <broonie@debian.org> - 2024-05-17 17:10 +0200
  Bug#1071276: Is 1:1.2.13.dfsg-1 affected by CVE-2023-45853, and if it is, will 1:1.3.dfsg-3.1 be backported to bookworm? Salvatore Bonaccorso <carnil@debian.org> - 2024-05-17 18:20 +0200
    Bug#1071276: Is 1:1.2.13.dfsg-1 affected by CVE-2023-45853, and if it is, will 1:1.3.dfsg-3.1 be backported to bookworm? John Waffle <jwaffe75@gmail.com> - 2024-05-17 22:10 +0200
      Bug#1071276: Is 1:1.2.13.dfsg-1 affected by CVE-2023-45853, and if it is, will 1:1.3.dfsg-3.1 be backported to bookworm? Salvatore Bonaccorso <carnil@debian.org> - 2024-05-18 11:10 +0200
        Bug#1071276: Is 1:1.2.13.dfsg-1 affected by CVE-2023-45853, and if it is, will 1:1.3.dfsg-3.1 be backported to bookworm? John Waffle <jwaffe75@gmail.com> - 2024-05-22 16:10 +0200
          Bug#1071276: Is 1:1.2.13.dfsg-1 affected by CVE-2023-45853, and if it is, will 1:1.3.dfsg-3.1 be backported to bookworm? John Waffle <jwaffe75@gmail.com> - 2024-05-24 20:10 +0200
            Bug#1071276: Is 1:1.2.13.dfsg-1 affected by CVE-2023-45853, and if it is, will 1:1.3.dfsg-3.1 be backported to bookworm? Salvatore Bonaccorso <carnil@debian.org> - 2024-05-24 21:50 +0200

csiph-web