2000 character limit reached
Tracking Patches for Open Source Software Vulnerabilities (2112.02240v2)
Published 4 Dec 2021 in cs.SE and cs.CR
Abstract: Open source software (OSS) vulnerabilities threaten the security of software systems that use OSS. Vulnerability databases provide valuable information (e.g., vulnerable version and patch) to mitigate OSS vulnerabilities. There arises a growing concern about the information quality of vulnerability databases. However, it is unclear what the quality of patches in existing vulnerability databases is; and existing manual or heuristic-based approaches for patch tracking are either too expensive or too specific to apply to all OSS vulnerabilities.
- Congying Xu (5 papers)
- Bihuan Chen (21 papers)
- Chenhao Lu (7 papers)
- Kaifeng Huang (11 papers)
- Xin Peng (82 papers)
- Yang Liu (2253 papers)