Tracking Patches for Open Source Software Vulnerabilities

Congying Xu,Bihuan Chen,Chenhao Lu,Kaifeng Huang,Xin Peng,Yang Liu
2023-09-30
Abstract:Open source software (OSS) vulnerabilities threaten the security of software systems that use OSS. Vulnerability databases provide valuable information (e.g., vulnerable version and patch) to mitigate OSS vulnerabilities. There arises a growing concern about the information quality of vulnerability databases. However, it is unclear what the quality of patches in existing vulnerability databases is; and existing manual or heuristic-based approaches for patch tracking are either too expensive or too specific to apply to all OSS vulnerabilities.
Software Engineering,Cryptography and Security
What problem does this paper attempt to address?