Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Data quality issue with CVE-2022-48434 #2930

Closed
sunSUNQ opened this issue Nov 28, 2024 · 4 comments
Closed

Data quality issue with CVE-2022-48434 #2930

sunSUNQ opened this issue Nov 28, 2024 · 4 comments
Labels
data quality Issues with data quality

Comments

@sunSUNQ
Copy link

sunSUNQ commented Nov 28, 2024

The CVE ID
CVE-2022-48434

Describe the data quality issue observed
The patch links can be improved more.

Suggested changes to record
CVE-2022-48434, which is documented on the official website . It mentions that the vulnerability has been addressed in five different branches with distinct patch commits. I would like to request the update of the patch links in the database, which are as follows:

Patch Link 1 For branch 6.0 & 5.1.2 & 5.0.1 & 4.4.3: FFmpeg/FFmpeg@cc867f2
Patch Link 2 For branch 5.1.2: FFmpeg/FFmpeg@35aa7e7
Patch Link 3 For branch 5.0.1: FFmpeg/FFmpeg@3bc28e9
Patch Link 4 For branch 4.4.3 & 4.3.7: FFmpeg/FFmpeg@d4b7b3c
Patch Link 5 For branch 4.3.7: FFmpeg/FFmpeg@031c960

@sunSUNQ sunSUNQ added the data quality Issues with data quality label Nov 28, 2024
Copy link

✨ Thank you for your interest in OSV.dev's data quality! ✨

Please review our FAQ entry on how to most efficiently have this addressed.

Copy link

This issue has not had any activity for 60 days and will be automatically closed in two weeks

See https://github.com/google/osv.dev/blob/master/CONTRIBUTING.md for how to contribute a PR if you're interested in helping out.

@github-actions github-actions bot added the stale The issue or PR is stale and pending automated closure label Jan 27, 2025
@sunSUNQ
Copy link
Author

sunSUNQ commented Jan 27, 2025 via email

@github-actions github-actions bot removed the stale The issue or PR is stale and pending automated closure label Jan 27, 2025
@andrewpollock
Copy link
Contributor

Hi @sunSUNQ, thanks for this feedback.

The CVE records in OSV.dev are programmatically converted from the NVD

The most appropriate way forward here is to get these commits added as references to the CVE in the CVE list

See:

@andrewpollock andrewpollock closed this as not planned Won't fix, can't repro, duplicate, stale Feb 4, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
data quality Issues with data quality
Projects
None yet
Development

No branches or pull requests

2 participants