Received: from mx0a-00069f02.pphosted.com (mx0a-00069f02.pphosted.com [205.220.165.32]) by gbr-app-1.alpinelinux.org (Postfix) with ESMTPS id 645D3226898 for <~alpine/users@lists.alpinelinux.org>; Mon, 21 Oct 2024 11:20:53 +0000 (UTC) Received: from pps.filterd (m0246617.ppops.net [127.0.0.1]) by mx0b-00069f02.pphosted.com (8.18.1.2/8.18.1.2) with ESMTP id 49L96cBt015911 for <~alpine/users@lists.alpinelinux.org>; Mon, 21 Oct 2024 11:20:50 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oracle.com; h= content-type:date:from:message-id:mime-version:subject:to; s= corp-2023-11-20; bh=thuL14mxXQPaaZPIYvbNSch/bTgc0HFzxO267UHXQw4=; b= WTcgROh/J8JdVGgt7YKxvna7VSjUA3ICmcqQIukSuu0VAm9YNKZipoREPIrHRC6w 3LaqWkP9DDF8TSiZ23dPFDTTC1TIRG0mAXP7iRpnWy0vsv+ntrJqbj4UyP7m4Kr1 NWkdKxzM21+bfTtN7ks5c8vqxFZPX+KfIsDu58NOzDXnRXo/qMNZc/PNW7wrZUtU rS45S9WC3Ckc1vszXj/tBeEo8BcxDvvZHnEgUrbkQ1XLM+96q1mVK93G7fQwmDe/ rJ5rxvCrGkvnylDBlFr1WnUW8+UJcFC3EB1xD1hYUYSn/LW8adF/HVqXUNDoz+Wk 3uYoAtC2i1JI1OSiPutodA== Received: from iadpaimrmta02.imrmtpd1.prodappiadaev1.oraclevcn.com (iadpaimrmta02.appoci.oracle.com [147.154.18.20]) by mx0b-00069f02.pphosted.com (PPS) with ESMTPS id 42c5asau9g-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK) for <~alpine/users@lists.alpinelinux.org>; Mon, 21 Oct 2024 11:20:49 +0000 (GMT) Received: from pps.filterd (iadpaimrmta02.imrmtpd1.prodappiadaev1.oraclevcn.com [127.0.0.1]) by iadpaimrmta02.imrmtpd1.prodappiadaev1.oraclevcn.com (8.18.1.2/8.18.1.2) with ESMTP id 49LAQrL7012015 for <~alpine/users@lists.alpinelinux.org>; Mon, 21 Oct 2024 11:20:48 GMT Received: from nam10-dm6-obe.outbound.protection.outlook.com (mail-dm6nam10lp2041.outbound.protection.outlook.com [104.47.58.41]) by iadpaimrmta02.imrmtpd1.prodappiadaev1.oraclevcn.com (PPS) with ESMTPS id 42c375xutj-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK) for <~alpine/users@lists.alpinelinux.org>; Mon, 21 Oct 2024 11:20:48 +0000 ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=vJVovKcQ8bkizvrXqtl5VcAIJJEj8CvbgQ5I15AiJDaa73uW1jZ0QJ35AQLx1LoG0m2BgqqQxsoX64gFSZfKhQyikVqUIFzUFimHQG3ERhH6xVH6nuOrAPzQrogbOCa2F+dGEvqdkpcf3QGewr1wXs6kiyGnLwu6qyoiGy4BgztSdjxjI2dCx7fhfp2+/Vrqfe1+6Iwf+raeOs6H95jdHodo6nwIHxoEBlJkaq+b1W820McKr3cns8lGOtx6c00Tv2pbL+H4mVCYZ1s/nQYbkB4FweXr08ud5enSAMIp9QI7WWDJqaidgpn/qrthVQAqCCO9W7K3+5UTP6mVsq0KBw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=thuL14mxXQPaaZPIYvbNSch/bTgc0HFzxO267UHXQw4=; b=LjCzjP6jXL9PxEEn1YLKnf6IFSefjBYAtiOR2I2qCjTBNMylP3IZQdNb9AD5KqtNQhKQ6csPKyCU0AD27Cpb6McPGlhrjlBLApWRXoaSUR0PHdA3dTjYfCS67SVuOgb8Zq9CRs1Z04tBfPX/eX5eFWabk6j/6rUC/fMNztNSom44hG+Dvedz8uavEbvkNNlfNZCGaTVx7R7K3M6zopw4y4xb0v6Cw+1UO2bvfspTA6dR4ptoIrQWiDNT5oUcvY2GxAP3CEGtgdY8WfKwjQgVfKjA3EX6Tq+qquygEtmg6JF3IhON6r5FsGM7DhtYEijgJUcGzk25+noAaC6Dx9UfXg== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=oracle.com; dmarc=pass action=none header.from=oracle.com; dkim=pass header.d=oracle.com; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oracle.onmicrosoft.com; s=selector2-oracle-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=thuL14mxXQPaaZPIYvbNSch/bTgc0HFzxO267UHXQw4=; b=gxwVuJgGDEdmlJhDnXUE23p+TDuDKmqZTkeUlP2obW9L1v8oH525HFIAaidDXKG70b0Ovy9x3yYwSS5c8ke7sTu6CHE2F0ymGNKNr7vUWKvgZ8wdocsGulpzbk+NfpG8abqlHqii1OCe6e6sGgqtrQmwdoe9pdINZ1l588VFbIk= Received: from DS0PR10MB6149.namprd10.prod.outlook.com (2603:10b6:8:c7::21) by IA0PR10MB7352.namprd10.prod.outlook.com (2603:10b6:208:40b::12) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.8069.28; Mon, 21 Oct 2024 11:20:46 +0000 Received: from DS0PR10MB6149.namprd10.prod.outlook.com ([fe80::61dd:522f:d49d:68bc]) by DS0PR10MB6149.namprd10.prod.outlook.com ([fe80::61dd:522f:d49d:68bc%4]) with mapi id 15.20.8069.027; Mon, 21 Oct 2024 11:20:46 +0000 From: Siddharth Srivastava To: "~alpine/users@lists.alpinelinux.org" <~alpine/users@lists.alpinelinux.org> Subject: Inquiry Regarding Resolution Timeline for CVE-2022-38725 in "syslog-ng" Package Thread-Topic: Inquiry Regarding Resolution Timeline for CVE-2022-38725 in "syslog-ng" Package Thread-Index: AQHbI6spuQlE2LuIMUChDjOXBVBTqw== Date: Mon, 21 Oct 2024 11:20:46 +0000 Message-ID: Accept-Language: en-IN, en-US Content-Language: en-IN X-MS-Has-Attach: X-MS-TNEF-Correlator: msip_labels: x-ms-publictraffictype: Email x-ms-traffictypediagnostic: DS0PR10MB6149:EE_|IA0PR10MB7352:EE_ x-ms-office365-filtering-correlation-id: cb638e21-1c49-492d-e7c6-08dcf1c268bb x-ms-exchange-senderadcheck: 1 x-ms-exchange-antispam-relay: 0 x-microsoft-antispam: BCL:0;ARA:13230040|1800799024|366016|10070799003|376014|38070700018|3613699012|8096899003; x-microsoft-antispam-message-info: =?iso-8859-1?Q?BkMMYF/SGx+zSusa7zZrQX/nR8hAGYSvr4UlXxhL5e/EGiqMjlJWXgmal7?= =?iso-8859-1?Q?a0kYutbVBTeyK+hCutwVA6F6skSH9aHID7fG21v47/piB8LSS9ZQZERGGU?= =?iso-8859-1?Q?uT7uiLuuCAgA02CnnxsfPqpiJfsEiHCJ89yvi3B+OzA8i07QW+6mXz4ZAC?= =?iso-8859-1?Q?dAfAylxKLyNA9yMhHTebTKtqw88sCwrqYe9dWIo7cNNgqqpIhvZWSZc5Cb?= =?iso-8859-1?Q?Jtf7YOzGqoh+x2JlQ4WoC6+jIGvBY5Iee1ftXYfoBv9yeLtF1eAU88nSvn?= =?iso-8859-1?Q?i56iKpNeq6ZPQtxZIAAMcTaEJ+2/q1OdP43INGxhCBtTQnp8rzQbQwftk3?= =?iso-8859-1?Q?7KFb9IBUtGnHlvw/HczH/FQ8WnPznpSwWxoJ2CWq+7wEtv8fgOU6JTzyoe?= =?iso-8859-1?Q?Kj9FIGE9XXAtnA0N+WLlQdrJ5DXPOUT0v3d58DBOXxv5Lx7HWQdKLgalBM?= =?iso-8859-1?Q?oxQeC/NTtAouwmH9M3HbU86ZalgFqGefFJYc8vUHqAu/Xg5IHMKw//o/CX?= =?iso-8859-1?Q?HBNouqf8M+YUGLFvnNqbANT1tYCb0RxEVTlKL5gGcP9n6KL8DIkdO/g3rW?= =?iso-8859-1?Q?RFe7i++negSuK4wjsZLUdF5AwQtjXwGhPpfLkXQi7wetQnE5sbQUGnch9q?= =?iso-8859-1?Q?YwDP++Uw6ID6VcCeQfwywtkgG1mJWpD3AHiBPW4IEdI3Q2Fv0Uagy80dp4?= =?iso-8859-1?Q?bDIg6HZEz8Vet7R7JTqnLS9ow1o127XJKMHpGCpS49EZF6M3d1QeQlfTWL?= =?iso-8859-1?Q?mXka57rzDPkPdvzYE4gMfQhufDhS8l7UOnbEQ0/S967SETya58goRNnxVi?= =?iso-8859-1?Q?8Hht/uoXqA2dPWWFgV2oJaUMBt0Csh1XMIiaFb1d3wkJ8ugkgehivKwRgo?= =?iso-8859-1?Q?/txNG6Wdv6AZXBCRZErRc02DdkMUO+r7vKLBAPKsUKvaXUHGT9avX18RVp?= =?iso-8859-1?Q?HqYzgiXPRMsvh140cqmauq3KBXimn/fNpsuHf/t+SbJqk/0d3BCKpqbM3w?= =?iso-8859-1?Q?Tc1XgsXdnL2bw0CycbZYe2XIM/yggmVQiDp2dJP4fa47krlcp8dVE8AW73?= =?iso-8859-1?Q?t1bK/lRJWedsaodUst+LZ+GBsLCJtYoD5rAcoUJQRlMMkMI9aKfLXqSwkC?= =?iso-8859-1?Q?h2Yc/17PBTnv1f+Aw5l+WV80EWitHG2A8nZdmz3B6yuK5hroFe5avTsZAr?= =?iso-8859-1?Q?KXqV/3nqH9f5gyXVBQkJWlJnfGXu9IKbj7Y8CuiNe+BJXJI/o8v1DKJSSK?= =?iso-8859-1?Q?HJFxXtVifbf/GeZHTCPoO2T+haq8xp7a5qUR+M43eg9+HvIp8qzzm6FpD9?= =?iso-8859-1?Q?GIiruVRm4P3R8NgGHCAhBz8yuhHiBA3DFB2ZzyaoT1VYQPGhvqed8x8vdJ?= =?iso-8859-1?Q?COdMLjvUIgCbns9L39OB9K3W5Ei3EcDaH3VNKDfszoxswMBtX4CdtAWAF2?= =?iso-8859-1?Q?SXFZUj/AeMrnmDlVWBUee31M3AOA/w06lALVOQ=3D=3D?= x-forefront-antispam-report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:DS0PR10MB6149.namprd10.prod.outlook.com;PTR:;CAT:NONE;SFS:(13230040)(1800799024)(366016)(10070799003)(376014)(38070700018)(3613699012)(8096899003);DIR:OUT;SFP:1101; x-ms-exchange-antispam-messagedata-chunkcount: 1 x-ms-exchange-antispam-messagedata-0: =?iso-8859-1?Q?0QjnqIp3ciMWyLYbLY6Kws9hX8vd/sSj/sUYrgnjqLwowHmnajwWiabBEh?= =?iso-8859-1?Q?jEAbZkKGkV9nj/iDsKjsMp54G6oTM7b9l3+fMx3lBnVYFoqYeHoD5c9m5D?= =?iso-8859-1?Q?2qfOKcwGwW9xPO30I0+CrfWe4tziNvwbvQqfBa5wwIH37ZmRBRmxDOXMB+?= =?iso-8859-1?Q?CJyDCDC7VFFSTwIcbxQU4T2/ifmpt42zQtdjq2IUPOjhjWDKWiNJ5yPToY?= =?iso-8859-1?Q?Hh3iYTUzsGRqA5Vo5SGq3aaQympytc7ZS2MXGJQdCnM0voQYO60KO9DUEi?= =?iso-8859-1?Q?vs6ejv6mN1W+Kby3PGG1K4NmND0su3YUNkMflq9xNI97NKLFhai6mAORRz?= =?iso-8859-1?Q?KocUtWUVW3NbfPN9mAMdVY3JHSlpSLyDQgHYQqr9pMmsxf5jCWfcIJPc5q?= =?iso-8859-1?Q?Dhzvuy/DVKocyT2THPz7LTJxz6tJd74mgfQFcTWAWVyvjwFlBN+afX52n9?= =?iso-8859-1?Q?/CSc4x5z7UZeXIbbux/pZt4QVHT4TAJ3Z7mwVK1JFIrC9ekuDztSfzAG8B?= =?iso-8859-1?Q?yqDcrzM36+nXXm5sWJRexflDCwNypCUDX3rFNZNEa82nGJvo2SqVaMk2sy?= =?iso-8859-1?Q?K0dkf5QGQKxVCCokTPsUbb2sp+XamhMzSxGquPCVUap24bv2KBqRZc2rZ/?= =?iso-8859-1?Q?PzovX0K3HQpgVAdJr7gU/HfAzMIKPAVjJTjLwiAHwxMM1TMJ+JpukO0Pwr?= =?iso-8859-1?Q?QrrLyf3DHRxdjIpYh8+XFQtxOwvokdCH8EtqzTJIOHcBNK3bFDerrSGEYP?= =?iso-8859-1?Q?SfZp/XMJ/fkWTs9fdJFF3IkyEQ6EgdSuPOZE/Ig8JO8xAj5TooL4wY3Y4A?= =?iso-8859-1?Q?lR/TiHfpKb4GazxYvkZirqAufMPjnIWVqbYTz0OFjG1rV/8hdgfiDZSZP8?= =?iso-8859-1?Q?00/DeZN6zCP2lzRsKm3dEMisF+Z7a12pnVleipiQgSGN33rUqaQC3y1Ghv?= =?iso-8859-1?Q?aQ9cMtBHSxP3ybBjnmpsG2cP8vWkn1cIfXlZYEjaQqqEIJ9oDiDLULnjzB?= =?iso-8859-1?Q?loxIVNw0rHkl069dP5FMgkwbs3rOUxqquJsrajGds/4NXKKp3q74CAdL8x?= =?iso-8859-1?Q?SvxRHpZp9ObIPwvqI+Q5dZk2ckTFzGyKKeZ0F5m6jESwdqveeMYJm4FqKx?= =?iso-8859-1?Q?ydhF9pfHOxSjtH8JMFgU0bK0JMAl/A5Hc4itEyNZAIChfWKjYP0FULQCs0?= =?iso-8859-1?Q?qzx1EqfNBBE+hT7SIbyssQxhSqHlqWH94+TKFzFN10PNUwnLfcGTxjcClK?= =?iso-8859-1?Q?3hUYtOX6vw9Nkmlij5pCcngFfZrprZ9IOoLniqvRFeOw6wOQvFrU8DpI6E?= =?iso-8859-1?Q?nUq7BOJlgv8aL04JmIr6tVWcC6S5gH5rkpIcCyJc8ELEEgR9IwU6GX+WIg?= =?iso-8859-1?Q?X43kTu8VU/AjrVKigwy/CRL3la9T+6drF7JexBT7uEodY6TrEHareeO+0v?= =?iso-8859-1?Q?s5eCJgLIXxZSu+n2sH+bud2psTyxGCOZQFVnCpuijBs2fcbyMFahPgA71t?= =?iso-8859-1?Q?meSSXqTLB1F3CEhzpYxI0KiSULZFAXWAyW7gms+MLTAnYyZqqUDeTCDKA5?= =?iso-8859-1?Q?pO3dibv3MZ+DHQmnVmwk1rF6COlo6FwwZt4PI9RSKeuQ9JqnUt10R9LV1Q?= =?iso-8859-1?Q?hAFR73ziCuCjwCW2GZa52TRzApE7KpgGMV19VhdTMlCZfCRA4tc3DlXdFj?= =?iso-8859-1?Q?bifuxXjO55spsH7Bq0dmHfQbyysyXA+xzmgMErPxw+yZ5hvZKxmqm1s6in?= =?iso-8859-1?Q?IJug=3D=3D?= Content-Type: multipart/alternative; boundary="_000_DS0PR10MB6149FEF0EB8BBF07DFFBB926A3432DS0PR10MB6149namp_" MIME-Version: 1.0 X-MS-Exchange-AntiSpam-ExternalHop-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-ExternalHop-MessageData-0: VBcsTa0xYRQMfjCyvcz7nOb2h6CytUqkMp0sI6UbKlu3ZhKxW1jL+Id/byIDLkf29FqtrWhttKykwxR1mAGNB84E68C/pVVCk5hJhNyc9nMhNG+148J9mwiw9GFO06f1vXACzpgu0l5UVD4agC9QhOR+H/ZKt9BHUgTOUuRNVUx7lYxEW/tmZ9qfV+SNQBjAhhmJ7/RyWAH+Hm4qdQ6IF3AhVo2U41SnBT7aieA4eT2hYzIn0LU6ZYMBpbb1r+/WPQxDpjGWBrjz/2PypHChmWABmrR1RRwbbjOMI6f5JPw2ATgQTIt0izuCb2IrnFfQIF5n+eHzshflXMPkQhjeHburoxzfTs3nHQdGpAfQzNZNrpjdkta/EzUs/tZscmG66mbVsDk/xvgC+JpPXK4VhK3nNdRUzJWqx3yakWKr2LQLvkltK1OeA/X9Vi9OTLsdNpqDJaiFbVC+YGC1jVFn5gV4o5eG1bqOB9OwA4AL2DQ8Q/Y7KA7w9dJ/KlDiJxEVkJw3t1/dCaxrRDOe+7qRnGfSxvoiuHKu5fHb38OVvz2GvHskeCfKrX+wkAtEc1FJfONSun3V0B6w8pN9wXZ08t2x7Agyy7vnta6HZQaU8ck= X-OriginatorOrg: oracle.com X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-AuthSource: DS0PR10MB6149.namprd10.prod.outlook.com X-MS-Exchange-CrossTenant-Network-Message-Id: cb638e21-1c49-492d-e7c6-08dcf1c268bb X-MS-Exchange-CrossTenant-originalarrivaltime: 21 Oct 2024 11:20:46.2748 (UTC) X-MS-Exchange-CrossTenant-fromentityheader: Hosted X-MS-Exchange-CrossTenant-id: 4e2c6054-71cb-48f1-bd6c-3a9705aca71b X-MS-Exchange-CrossTenant-mailboxtype: HOSTED X-MS-Exchange-CrossTenant-userprincipalname: W6FSPdh6bv1CyPORyNxEDaxk43Xvclr/lt1qh4602lBB2AMQIQz+jZ9h/y8sTBQd4Z09kvOSHp4yILUtT+u+UdYO+an60qlHxgHK2GDo2YEf1R3f8a+6sFSUSfTNQ9aN X-MS-Exchange-Transport-CrossTenantHeadersStamped: IA0PR10MB7352 X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1051,Hydra:6.0.680,FMLib:17.12.62.30 definitions=2024-10-21_08,2024-10-21_01,2024-09-30_01 X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 bulkscore=0 malwarescore=0 suspectscore=0 adultscore=0 mlxscore=0 spamscore=0 mlxlogscore=999 phishscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.12.0-2409260000 definitions=main-2410210081 X-Proofpoint-GUID: 0tUjI-yQR_VE9Oap3uWYoOIgWR3R88rv X-Proofpoint-ORIG-GUID: 0tUjI-yQR_VE9Oap3uWYoOIgWR3R88rv --_000_DS0PR10MB6149FEF0EB8BBF07DFFBB926A3432DS0PR10MB6149namp_ Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable Dear Alpine Security Team, Writing to inquire about the status of CVE-2022-38725, which affects the "s= yslog-ng" package in the 3.20-main branch. According to the Alpine Security= Tracker, this CVE remains unresolved, and we are seeing it flagged in the = latest images we are using. Could you please provide an update on when this= vulnerability is expected to be resolved or if there are any planned fixes= ? T Thank you. Best regards, Siddharth Srivastava --_000_DS0PR10MB6149FEF0EB8BBF07DFFBB926A3432DS0PR10MB6149namp_ Content-Type: text/html; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable
Dear Alpine Security Team,
Writing to inquire about the status of CVE-2022-38725, which affects the &q= uot;syslog-ng" package in the 3.20-main branch. According to the Alpin= e Security Tracker, this CVE remains unresolved, and we are seeing it flagg= ed in the latest images we are using. Could you please provide an update on when this vulnerability is expected to be = resolved or if there are any planned fixes? T
Thank you.
Best regards,
Siddharth Srivastava

--_000_DS0PR10MB6149FEF0EB8BBF07DFFBB926A3432DS0PR10MB6149namp_--