2 ms·
What is a security vulnerability in a library here? Do you mean something like using `numpy.frombuffer` to mutate strings in place, or using `numpy.lib.stride_t
by joejev 10y ago
What is a security vulnerability in a library here? Do you mean something like using `numpy.frombuffer` to mutate strings in place, or using `numpy.lib.stride_tricks` to access invalid addresses?
Maybe this is something like functions calls which use improper sql escaping? I am not sure what is being detected.
- resoluteteeth 10y agoBased on "update at a more leisurely pace" I'm guessing it's literally just looking for specific methods from libraries covered by security advisories, which is much less interesting than what you are imagining.
- briandoll 10y agoA specific disclosed vulnerability found in an open source library. As you might guess, most folks don't file CVEs (https://cve.mitre.org/ https://cve.mitre.org/). Our research team maintains a database of vulnerabilities that includes published CVEs, but also includes vulnerabilities we've identified. Here's an example of some vulnerabilities that we discovered, disclosed, and now have in our database: https://blog.sourceclear.com/copy-paste-vulnerability-disclosure/ https://blog.sourceclear.com/copy-paste-vulnerability-disclo... The full vulnerability database is online here: https://www.sourceclear.com/registry/explore https://www.sourceclear.com/registry/explore