Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2019-5482 and CVE-2019-18224 #1261

Closed
adriangonz opened this issue Dec 13, 2019 · 2 comments
Closed

CVE-2019-5482 and CVE-2019-18224 #1261

adriangonz opened this issue Dec 13, 2019 · 2 comments
Assignees
Labels
Milestone

Comments

@adriangonz
Copy link
Contributor

adriangonz commented Dec 13, 2019

There are a couple of vulnerabilities present on the seldonio/engine:0.5.2-SNAPSHOT image.

After looking into both, they both seem to affect packages which are installed through Debian (seldonio/engine is build from openjdk, which is based on Debian Buster). Therefore, we need for them to first update these dependencies upstream. After that's done, we should be able to just re-build the image and install the latest versions.

CVE-2019-5482

Reported as http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-5482.

Affects cURL, from 7.19.4 to 7.65.3.
This issue has already been raised in Debian's bugtracking system.
The fixed version is already in the "testing" channel.
https://security-tracker.debian.org/tracker/CVE-2019-5482

CVE-2019-18224

Reported as http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-18224.

Affects libidn2 up to 2.1.1.
This issue has already been raised in Debian's bugtracking system.
The fixed version is already in the "testing" channel.
https://security-tracker.debian.org/tracker/CVE-2019-18224

@adriangonz adriangonz added bug triage Needs to be triaged and prioritised accordingly and removed triage Needs to be triaged and prioritised accordingly labels Dec 13, 2019
@adriangonz adriangonz added this to the 1.0 milestone Dec 13, 2019
@adriangonz
Copy link
Contributor Author

libidn2 seems to be a dependency of libc6, which is a dependency of a few basic packages which we can't remove. Therefore, we can only wait until they move the fix to the stable channel of Debian.

On the other hand, curl doesn't seem to be needed on the seldonio/engine image, so we should be able to remove it.

@adriangonz
Copy link
Contributor Author

CVE-2019-5482 should be fixed by #1264 and CVE-2019-18224 is now tracked in #1286

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

2 participants