Vulnerabilities

1 via 1 paths

Dependencies

17

Source

Group 6 Copy Created with Sketch. Docker

Target OS

alpine:3.12.12
Test your Docker Hub image against our market leading vulnerability database Sign up for free
Severity
  • 1
Status
  • 1
  • 0
  • 0

critical severity

Out-of-bounds Write

  • Vulnerable module: zlib/zlib
  • Introduced through: zlib/zlib@1.2.12-r0
  • Fixed in: 1.2.12-r2

Detailed paths

  • Introduced through: amazoncorretto@8-alpine3.12-full zlib/zlib@1.2.12-r0

NVD Description

Note: Versions mentioned in the description apply only to the upstream zlib package and not the zlib package as distributed by Alpine. See How to fix? for Alpine:3.12 relevant fixed versions and status.

zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the nodejs/node reference).

Remediation

Upgrade Alpine:3.12 zlib to version 1.2.12-r2 or higher.

References