Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
feat: enhance products with no identified vulnerabilities (intel#3254)
Currently, cve-bin-tool will return gnu:zlib in "Products with No Identified Vulnerabilities" if zlib is found but not affected by CVE-2016-9842 (i.e. zlib >= 1.2.9) because NVD NIST database contains two CPE IDs for zlib (gnu:zlib and zlib:zlib) With this update, product with multiple vendors will not be displayed under above section if a CVE is found with one of the vendor. Fix intel#3169 Signed-off-by: Fabrice Fontaine <fabrice.fontaine@orange.com>
- Loading branch information