aboutcode-org / aboutcode-org/vulnerablecode

Rust Sec DB ambiguous version ranges

未关闭
#584 2 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
bug import-improver-migration
主要语言
Python
星标
702
派生
328
平均合并
3 天 8 小时
30 天内合并 PR
3

描述

https://github.com/rustsec/advisory-db/blob/main/crates/futures-util/RUSTSEC-2020-0059.md has intersecting affecting and patched version ranges.

It mentions:

Affected Range: >= 0.3.2
Patched Range: >= 0.3.7

Hence VC gets confused about whether >= 0.3.7 are really patched.

In a trivial case like this somehow we could infer ">=0.3.2, <0.3.7" is vulnerable. But in complex cases of multiple affected ranges and patched ranges, pairing the ranges to form closed interval will be non trivial and sometimes wrong.

Also the OSV version of the advisory at https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2020-0059.json doesn't really help since the "events" are not connected.

贡献指南

这个仓库没有索引到贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。