Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

nvd-cve-osv: OpenSSL versions do not normalize correctly #2220

Open
andrewpollock opened this issue May 17, 2024 · 0 comments
Open

nvd-cve-osv: OpenSSL versions do not normalize correctly #2220

andrewpollock opened this issue May 17, 2024 · 0 comments

Comments

@andrewpollock
Copy link
Contributor

OpenSSL's versions aren't being normalized very well, by the Go code or the Python code (unsurprising, given they're supposed to behave the same):

OpenSSL_1_1_1w winds up getting normalized to 1-1-1 and when there's OpenSSL_1_1_1a to OpenSSL_1_1_1w (as well as OpenSSL_1_1_1) they're all overwriting each other during normalization and the last one wins.

Originally posted by @andrewpollock in #1984 (comment)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant