Skip to content
This repository has been archived by the owner on Jan 3, 2019. It is now read-only.

Multiple Vulnerabilities in php 7.0.x #90

Closed
kujiy opened this issue Jul 13, 2017 · 1 comment
Closed

Multiple Vulnerabilities in php 7.0.x #90

kujiy opened this issue Jul 13, 2017 · 1 comment

Comments

@kujiy
Copy link

kujiy commented Jul 13, 2017

Thank you for sharing your excellent product!

php:7.0-apache has vulnerabilities. Could you rebuild the images from php:7.1-apache?

https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-php-could-allow-for-arbitrary-code-execution/

@tianon
Copy link
Member

tianon commented Apr 20, 2018

This is similar to docker-library/openjdk#161, docker-library/openjdk#112, docker-library/postgres#286, docker-library/drupal#84, docker-library/official-images#2740, docker-library/ruby#117, docker-library/ruby#94, docker-library/python#152, docker-library/php#242, docker-library/buildpack-deps#46, docker-library/openjdk#185.

The TL;DR is that most of the CVEs reported in these images end up being either false positives or deemed to be of low impact/priority by the Debian security team. For major security issues, we do automatically rebuild images as promptly as possible.

@tianon tianon closed this as completed Apr 20, 2018
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants