Hacker News new | ask | show | jobs
by s14ve 2596 days ago
I believe it's public on their GitHub since 5 Aug 2018. https://github.com/gliderlabs/docker-alpine/issues/430

> 2019-03-01 - It was discovered that this issue was also reported and made public in their Github prior to our report, but was not flagged as a security issue and thus remained unresolved until it was rediscovered and reported by Cisco.

https://talosintelligence.com/vulnerability_reports/TALOS-20...

1 comments

> https://github.com/gliderlabs/docker-alpine/issues/430

That issue is claimed to have been fixed, with a reference to a commit of the updated images, says issue 430 is a security issue and closed, but no link to the actual fix.

Word to the wise folks: If you are fixing bugs by posting binaries, it's a good idea to include a reference to the git hash of the actual fixes you've built those binaries with.