aboutcode-org / aboutcode-org/vulnerablecode

Rust Sec DB ambiguous version ranges

Open
#584 2 comments 0 reactions 0 assignees View on GitHub
bug import-improver-migration
Dominant language
Python
Stars
702
Forks
328
Avg merge
3d 8h
Merged PRs (30d)
3

Description

https://github.com/rustsec/advisory-db/blob/main/crates/futures-util/RUSTSEC-2020-0059.md has intersecting affecting and patched version ranges.

It mentions:

Affected Range: >= 0.3.2
Patched Range: >= 0.3.7

Hence VC gets confused about whether >= 0.3.7 are really patched.

In a trivial case like this somehow we could infer ">=0.3.2, <0.3.7" is vulnerable. But in complex cases of multiple affected ranges and patched ranges, pairing the ranges to form closed interval will be non trivial and sometimes wrong.

Also the OSV version of the advisory at https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2020-0059.json doesn't really help since the "events" are not connected.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.