Joydeep Tripathy

Results 10 issues of Joydeep Tripathy

Added checker for Google Chrome as I saw it missing in the checker list

This experiment is an extension of the CI-Pre-Checker github action. https://github.com/intel/cve-bin-tool/pull/3840 This script aims to print any and all the checkers which have {product,version} pairs in their VENDOR_PRODUCT which do...

blocked

Following the discussion on https://github.com/intel/cve-bin-tool/issues/3841 , I propose that we should add a [unblob](https://github.com/onekey-sec/unblob) based tarfile extractor, since the 'tarfile' library is vulnerable to path traversal, and thus has a...

### Description cve-bin-tool has an [existing fuzz testing setup](https://github.com/intel/cve-bin-tool/tree/main/fuzz) which is based on Google Atheris. One of the areas it doesn't yet cover is the files used by the language...

### Description cve-bin-tool has an [existing fuzz testing setup](https://github.com/intel/cve-bin-tool/tree/main/fuzz) which is based on Google Atheris. One of the areas it doesn't yet cover is the files used by the language...

In my recent commit to my PR https://github.com/intel/cve-bin-tool/pull/3543 bandit linter shows that the used library **tarfile** has high severity_score. However, I went through all the documentations of the repo and...

Related #4045 Related to fuzzing run https://github.com/intel/cve-bin-tool/actions/runs/8595897802. ![18 04 2024_23 43 49_REC](https://github.com/intel/cve-bin-tool/assets/113792434/f70ed15a-c798-4ec2-9a5e-2f52e9e1b80d)

good first issue

Related #4045 ![20 04 2024_00 11 24_REC](https://github.com/intel/cve-bin-tool/assets/113792434/6fb6dcac-3f3c-44d0-88de-c2cd1cd90c74)