[issue2551268] Clear grype reports of CVE-2022-3515 issues with gpg in docker container

John Rouillard <[email protected]> Sat, 04 Mar 2023 21:51:45 +0000
Newsgroups gmane.comp.bug-tracking.roundup.devel
Message-ID <[email protected]>
New submission from John Rouillard:

It looks like the library affected by the CVE was fixed by alpine. But the gpg toolchain
linked with it was not rebuilt against the fixed statically linked library.

Opened:

  https://gitlab.alpinelinux.org/alpine/aports/-/issues/14682

----------
assignee: rouilj
components: Mail interface
messages: 7738
nosy: rouilj
severity: normal
status: new
title: Clear grype reports of CVE-2022-3515 issues with gpg in docker container
type: security

_________________________________________________
Roundup tracker <[email protected]>
<https://issues.roundup-tracker.org/issue2551268>
_________________________________________________