-
Notifications
You must be signed in to change notification settings - Fork 506
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
fix: NVD cpe parser doesn't escape \:
's in product and vendor name
#4041
Labels
bug
Something isn't working
Comments
assign it to me please |
\
's in product and vendor name
\
's in product and vendor name\:
's in product and vendor name
good finding, thanks for working on it! |
Hello @fthdrmzzz |
fthdrmzzz
added a commit
to MadriSec/cve-bin-tool
that referenced
this issue
Apr 20, 2024
Signed-off-by: fthdrmzzz <mail.fatih.durmaz@gmail.com>
terriko
added a commit
that referenced
this issue
Apr 25, 2024
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Description
Hello, I think I have noticed a small bug
In nvd_source.py the product data is splitted by
:
.However, in some cases there is
data:image/s3,"s3://crabby-images/2fbc3/2fbc31ab20e2577fc80d1600c05975a8f56e24ea" alt="image"
:
in the name of the vendor or the product and NVD escapes these:
's by putting a backslash in front. Example here:This results in recording the product as
\
in the database. To see it, I have made a simple sql query to the mysql database stored in~/.cache/cve-bin-tool/cve.db
to check and see it:I don't know what are the effects of this bug on tool's behavior. Maybe it might miss some cve's on binaries that it was supposed to hit.
Please assign me for this.
The text was updated successfully, but these errors were encountered: