Skip to content

CVE-2024-6119 not detected #7525

Closed Answered by DmitriyLewen
johnsenong asked this question in Q&A
Discussion options

You must be logged in to vote

Hello @johnsenong
Sorry for the confusion. I answered the question in my head 😄

Let me just say a few things:

  1. about apt packages:
    This image contains installed libssl3t64 and libssl-dev packages. Source of these packages - openssl (see https://packages.debian.org/sid/libssl3t64).
    Trivy finds vulnerabilities by source package, but show package name (to make it easier for you to find and update it via apt).
    So Trivy detects CVE-2024-6119 (you can see full info using -f json --list-all-pkgs flags):
{
        "ID": "libssl-dev@3.0.13-0ubuntu3.3",
        "Name": "libssl-dev",
        "Identifier": {
          "PURL": "pkg:deb/ubuntu/libssl-dev@3.0.13-0ubuntu3.3?arch=arm64\u0026distro=ubuntu…

Replies: 4 comments 2 replies

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
1 reply
@DmitriyLewen
Comment options

Answer selected by johnsenong
Comment options

You must be logged in to vote
1 reply
@DmitriyLewen
Comment options

Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
triage/support Indicates an issue that is a support question.
2 participants