cve-bin-tool icon indicating copy to clipboard operation
cve-bin-tool copied to clipboard

New checker: Oracle jre (java runtime environment)

Open terriko opened this issue 4 years ago • 4 comments

New checker request: Oracle jre (java runtime environment)

Website: https://www.oracle.com/java/technologies/javase-jre8-downloads.html

CVEs: https://www.cvedetails.com/product/19117/Oracle-JRE.html?vendor_id=93

Instructions: How to add a new checker to the CVE Binary Tool

(Note: This was filed from the list in #709)

terriko avatar Jan 21 '21 22:01 terriko

@terriko just wanted to be sure of this , when we are running the checkers test then internally the rpm files are downloaded right? if its the case then we might have issues downloading the oracle jre without logging, and the rpm might not be loaded , Actually I was facing this issue in my PR for a long time , So just wanted to confirm about it.

Pratikrocks avatar Mar 12 '21 18:03 Pratikrocks

Yes, the rpms will be downloaded. if the download fails to get the file then the test will fail (at least until you get a download and create a condensed file, at which point the test will use the condensed file instead of re-downloading)

terriko avatar Mar 18 '21 23:03 terriko

@terriko @Pratikrocks: As the PR for this checker has not yet been merged should I go ahead and give this one a shot?

alt-glitch avatar Apr 03 '21 12:04 alt-glitch

Had some challenges with getting approrpriate binaries to test. I'm going to take the "good first issue" flag off this as it may take more work.

terriko avatar Jul 15 '21 20:07 terriko

It's been a few years and this one is still challenging and hasn't garnered interest. Going to go ahead and close it.

terriko avatar Apr 17 '24 21:04 terriko