aboutcode-org / aboutcode-org/scancode-plugins

Known vulnerabilities in shared library which extractcode-libarchive depends on.Can you help upgrade to patch versions?

オープン
#21 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る
主要言語
HTML
スター
2
フォーク
11
PR マージ指標
30日以内にマージされた PR はありません

説明

Hi, @pombr , @JonoYang, I'd like to report a vulnerability issue in **extractcode-libarchive_3.5.1.210531**.
### Dependency Graph between Python and Shared Libraries
![image](https://user-images.githubusercontent.com/101270230/161099244-ec324143-d9fe-4c7e-baf1-7b882388a5e7.png)
### Issue Description
As shown in the above dependency graph(just shows the vulnerable dependency), **extractcode-libarchive_3.5.1.210531** directly depends on ***8*** C libraries (.so). However, I noticed that one C library is vulnerable, containing the following CVEs:
`libarchive.so` from C project **libarchive(version:3.4.3)** exposed ***1*** vulnerabilities:
[CVE-2021-36976](https://nvd.nist.gov/vuln/detail/CVE-2021-36976)

### Suggested Vulnerability Patch Versions
***libarchive*** has fixed the vulnerabilities in versions ***>=3.5.3***

Python build tools cannot report vulnerable C libraries, which may induce potential security issues to many downstream Python projects.
As a popular python package (**extractcode-libarchive** has **8,456** downloads per month), could you please upgrade the above shared libraries to their patch versions?

Thanks for your help~
Best regards,
Andy

コントリビューションガイド

このリポジトリのコントリビューションガイドは索引されていません

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。