Nix-Security-WG / nix-security-tracker

Web service for managing information on vulnerabilities in software distributed through Nixpkgs
26 stars 4 forks source link

False positive: CVE-2015-1773 in flex #137

Open raboof opened 9 months ago

raboof commented 9 months ago

The package is https://github.com/westes/flex , but the advisory is for https://flex.apache.org/ (cpe cpe:2.3:a:apache:flex:*:*:*:*:*:*:*:*)

Here, looking at the pname seems insufficient to reliably match the package.

Possible solution: #136