vulnerablecode icon indicating copy to clipboard operation
vulnerablecode copied to clipboard

Add SUDO Advisories

Open kunalsz opened this issue 9 months ago • 2 comments

In reference to the issue #470

Changes made

  • Added a new pipeline for SUDO advisories

kunalsz avatar Mar 20 '25 19:03 kunalsz

While testing the importer using the command ./manage.py import sudo_importer I get this error

ERROR 2025-03-20 19:10:25.104 Error while processing AdvisoryData(aliases=['CVE-2023-27320'], summary='A flaw exists in sudo’s per-command chroot feature that could result\nin the variable that stores the command being freed more than once.', affected_packages=[AffectedPackage(package=PackageURL(type='sudo', namespace=None, name='SUDO', version=None, qualifiers={}, subpath=None), affected_version_range=GenericVersionRange(constraints=(VersionConstraint(comparator='<=', version=SemverVersion(string='1.9.8')), VersionConstraint(comparator='>=', version=SemverVersion(string='1.9.13p1')))), fixed_version=SemverVersion(string='1.9.13p2'))], references=[Reference(reference_id='CVE-2023-27320', reference_type='', url='https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-27320', severities=[])], date_published=datetime.datetime(2023, 2, 27, 8, 0, tzinfo=datetime.timezone.utc), weaknesses=[], url='https://www.sudo.ws/security/advisories/double_free/') with aliases ['CVE-2023-27320']: DataError('value too long for type character varying(32)\n')

@pombredanne @TG1999 @keshav-space

kunalsz avatar Mar 21 '25 10:03 kunalsz

Thanks. You are missing a DCO signoff.

pombredanne avatar Apr 03 '25 15:04 pombredanne