aboutcode-org / aboutcode-org/vulnerablecode

Rust Sec DB ambiguous version ranges

未關閉
#584 2 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
bug import-improver-migration
主要語言
Python
星號
702
分支
328
平均合併
3 天 8 小時
30 天內合併 PR
3

描述

https://github.com/rustsec/advisory-db/blob/main/crates/futures-util/RUSTSEC-2020-0059.md has intersecting affecting and patched version ranges.

It mentions:

Affected Range: >= 0.3.2
Patched Range: >= 0.3.7

Hence VC gets confused about whether >= 0.3.7 are really patched.

In a trivial case like this somehow we could infer ">=0.3.2, <0.3.7" is vulnerable. But in complex cases of multiple affected ranges and patched ranges, pairing the ranges to form closed interval will be non trivial and sometimes wrong.

Also the OSV version of the advisory at https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2020-0059.json doesn't really help since the "events" are not connected.

貢獻指南

這個儲存庫沒有索引到貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。