CVE-2024-3094 is flagged for xz-libs-5.4.6-r0 #6472
Closed
venkatasandeeplade
started this conversation in
False Detection
Replies: 1 comment
-
Duplicate of #6448 |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
IDs
CVE-2024-3094
Description
Team
In our image , CVE-2024-3094 is flagged though xz-lib version is xz-libs-5.4.6-r0
`ccc85caee824:~# apk info xz-libs
xz-libs-5.4.5-r0 description:
Library and CLI tools for XZ and LZMA compressed files (libraries)
xz-libs-5.4.5-r0 webpage:
https://tukaani.org/xz
xz-libs-5.4.5-r0 installed size:
232 KiB
xz-libs-5.4.6-r0 description:
Library and CLI tools for XZ and LZMA compressed files (libraries)
xz-libs-5.4.6-r0 webpage:
https://xz.tukaani.org/xz-utils/
xz-libs-5.4.6-r0 installed size:
232 KiB
`
But as per https://security.alpinelinux.org/vuln/CVE-2024-3094 versions below 5.6.0 are not vulnerable
Reproduction Steps
Target
Container Image
Scanner
Vulnerability
Target OS
Alpine Linux
Debug Output
Version
Checklist
-f json
that shows data sources and confirmed that the security advisory in data sources was correctBeta Was this translation helpful? Give feedback.
All reactions