Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[matio] How to fix/remove 2021-440? #12

Closed
tbeu opened this issue Nov 23, 2021 · 3 comments
Closed

[matio] How to fix/remove 2021-440? #12

tbeu opened this issue Nov 23, 2021 · 3 comments

Comments

@tbeu
Copy link
Contributor

tbeu commented Nov 23, 2021

CVE-2020-36428 = OSV-2021-440 = https://oss-fuzz.com/testcase-detail/5668218489536512 is considered invalid. How can both CVE and OSV be marked as fixed?

@fyi @inferno-chromium

@tbeu tbeu changed the title How to fix/remove2021-440? How to fix/remove 2021-440? Nov 23, 2021
@tbeu tbeu changed the title How to fix/remove 2021-440? [matio] How to fix/remove 2021-440? Nov 23, 2021
@oliverchang
Copy link
Collaborator

It's not fixed according to the OSV. https://osv.dev/vulnerability/OSV-2021-440 has an "introduced" event only, and no "fixed" event.

We also don't generate the CVE -- someone else is taking our entries and generating them.

@tbeu
Copy link
Contributor Author

tbeu commented Nov 25, 2021

Yes, I know, it is not marked as fixed in the yaml file. But I thought it is considered a false-positive issue and wondered how to deal with it.

@oliverchang
Copy link
Collaborator

Ah, I misunderstood your question. After your PR, https://osv.dev/vulnerability/OSV-2021-440 is marked as fixed, thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants