intel / cve-bin-tool

The CVE Binary Tool helps you determine if your system includes known vulnerabilities. You can scan binaries for over 200 common, vulnerable components (openssl, libpng, libxml2, expat and others), or if you know the components used, you can get a list of known vulnerabilities associated with an SBOM or a list of components and versions.
https://cve-bin-tool.readthedocs.io/en/latest/
GNU General Public License v3.0
1.14k stars 444 forks source link

Added YAFFS as valid binary file #4201

Closed gvozzolo closed 2 weeks ago

gvozzolo commented 2 weeks ago

Based on https://github.com/intel/cve-bin-tool/issues/4199 I've tested a bunch of files and the only different output I've found is for YAFFS files; so I'm proposing to add the YAFFS flag in the is_executable function so it works as expected.