Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2022-2068,CVE-2016-2176,CVE-2020-10143这几个问题有修改计划吗? #650

Open
wsg314 opened this issue Sep 2, 2024 · 4 comments

Comments

@wsg314
Copy link

wsg314 commented Sep 2, 2024

CVE-2022-2068CVE-2016-2176CVE-2020-10143这几个漏洞有修改计划吗?

@dongbeiouba
Copy link
Member

CVE-2022-2068CVE-2016-2176CVE-2020-10143这几个漏洞有修改计划吗?

请问,是如何检测Tongsuo存在这些漏洞的?

我只看了一下CVE-2022-2068,Tongsuo项目中已经删除了c_rehash.in脚本文件,既然都不存在该文件,怎么可能存在CVE-2022-2068漏洞呢

您确定不是误报吗?

@wsg314
Copy link
Author

wsg314 commented Sep 4, 2024

FOSSEys系统扫描的,使用的是Tongsuo 8.5.0的源码包

@dongbeiouba
Copy link
Member

FOSSEys系统扫描的,使用的是Tongsuo 8.5.0的源码包

FOSSEys扫描器是开源的?还是商业化产品?可以了解一下他们扫描漏洞的原理,反馈一下误报。

@InfoHunter
Copy link
Member

有可能是根据OpenSSL版本信息得出的漏洞……

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants