Skip to content

Behaviour of 'arch' param in debian package request #582

Description

@nnobelis

Hello,

This is more a question than a bug.
The api/docs of VulnerableCode gives the following quest example:
pkg:deb/debian/curl@7.50.3-1?arch=i386&distro=jessie

I try to play with the arch param.
If I query pkg:deb/debian/apt@2.2.4?distro=bullseye to VulnerableCode I receive:


  {
    "url": "http://localhost:9999/api/packages/613937",
    "unresolved_vulnerabilities": [
      {
        "url": "http://localhost:9999/api/vulnerabilities/7783",
        "vulnerability_id": "CVE-2011-3374",
        "references": [
          {
            "reference_id": "CVE-2011-3374",
            "url": "https://nvd.nist.gov/vuln/detail/CVE-2011-3374",
            "scores": [
              [...]

And if I look on https://security-tracker.debian.org/tracker/CVE-2011-3374 I see that all versions are vulnerable.

Then when I query
pkg:deb/debian/apt@2.2.4?distro=bullseye&arch=amd64
why do I get no vulnerabilities ?

[
  {
    "type": "deb",
    "namespace": "debian",
    "name": "apt",
    "version": "2.2.4",
    "qualifiers": {
      "arch": "amd64",
      "distro": "bullseye"
    },
    "subpath": null,
    "unresolved_vulnerabilities": [],
    "resolved_vulnerabilities": [],
    "purl": "pkg:deb/debian/apt@2.2.4?distro=bullseye&arch=amd64"
  }
]

Shouldn't the same vulnerability be returned since it affects all versions ?

Version of VulnerableCode used: 4677f70

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions