Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2023-45853 for dotnet:4-slim image #1130

Open
asos-sasamilovic opened this issue Aug 12, 2024 · 1 comment
Open

CVE-2023-45853 for dotnet:4-slim image #1130

asos-sasamilovic opened this issue Aug 12, 2024 · 1 comment

Comments

@asos-sasamilovic
Copy link

Hi, we are getting this when scanning with snyk

✗ Critical severity vulnerability found in zlib/zlib1g
Description: Integer Overflow or Wraparound
Info: https://security.snyk.io/vuln/SNYK-DEBIAN11-ZLIB-6008961
Introduced through: zlib/zlib1g@1:1.2.11.dfsg-2+deb11u2
From: zlib/zlib1g@1:1.2.11.dfsg-2+deb11u2
Image layer: Introduced by your base image (mcr.microsoft.com/azure-functions/dotnet:4-slim)

@FinVamp1
Copy link
Member

FinVamp1 commented Aug 19, 2024

• From what we have concluded this is a false positive detection in the Debian images. Unfortunately there's a ton of Debian based container images that will get flagged, Debian is a very popular base image.
• The source code of that particular version of zlib has a vulnerability, but the vulnerable part isn't in the Debian package. The Debian binary for zlib doesn't contain the vulnerable code.

This reference link discusses it in more detail:
ZLib Issue Discussion

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants