From 4ff0ca3d71de5fc07f3203e6b7b5cbb6a8ecda7e Mon Sep 17 00:00:00 2001 From: Fabrice Fontaine Date: Wed, 10 May 2023 11:02:52 +0200 Subject: [PATCH] fix: improve lua checker Improve lua checker to avoid false positives with haproxy, nmap, vim and wireshark binaries which link dynamically with lua library (and save the associated version number) While at it, add an OpenWRT test package Signed-off-by: Fabrice Fontaine --- cve_bin_tool/checkers/lua.py | 2 +- .../liblua5.1.5_5.1.5-3_x86_64.ipk.tar.gz | Bin 0 -> 9664 bytes test/test_data/haproxy.py | 3 +-- test/test_data/lua.py | 6 ++++++ test/test_data/nmap.py | 1 - test/test_data/vim.py | 1 - test/test_data/wireshark.py | 1 - 7 files changed, 8 insertions(+), 6 deletions(-) create mode 100644 test/condensed-downloads/liblua5.1.5_5.1.5-3_x86_64.ipk.tar.gz diff --git a/cve_bin_tool/checkers/lua.py b/cve_bin_tool/checkers/lua.py index 612bd3cdcb..ceef700c17 100644 --- a/cve_bin_tool/checkers/lua.py +++ b/cve_bin_tool/checkers/lua.py @@ -17,5 +17,5 @@ class LuaChecker(Checker): r"-o name output to file `name' \(default is \"luac.out\"\)", ] FILENAME_PATTERNS = [r"lua"] - VERSION_PATTERNS = [r"Lua ([0-9]+\.[0-9]+\.[0-9]+)"] + VERSION_PATTERNS = [r"Lua ([0-9]+\.[0-9]+\.[0-9]+) "] VENDOR_PRODUCT = [("lua", "lua")] diff --git a/test/condensed-downloads/liblua5.1.5_5.1.5-3_x86_64.ipk.tar.gz b/test/condensed-downloads/liblua5.1.5_5.1.5-3_x86_64.ipk.tar.gz new file mode 100644 index 0000000000000000000000000000000000000000..8ab7d49191ad3244402e57245098823ebf39bf57 GIT binary patch literal 9664 zcmds(RZkoafW&ckcW7}h?o!;{i@Qtl#oeJev`BHb=;H3~?yif&;(q_!H@MeJCi5`K z?`bm0P{tu4K|?`7!F)Q}nLB!#@vw2Q@tFLtvvQgE@bjARa+*0ngK@}Gv$aX>~nF~Y~~4LJ15&DI5eOUJ6BL;HF8bF?D-EHjh+Fvj8J8L~W9 z(>-9-)?xT@I9T(^sqp#I?HUnM7l8Iz^C?#IY4^kBb2;dJIS4n;vRkY?)l6x$Wvfhf zb6Shj+3po`haceYp;U48`C+{E_slmFutdiT0V?5yIy zgJ6a=g*7wF-rZhNZmEIWbOSg)jEng8YZ}_$xyYY%T^>#j54b#kE3XCF3wn4zUI`h9 z_*+wI6t#IOPv;wJx^R;-o}yp(_)H~C%KHhwtV=gty+RV-%hkm&x(S;O-YmpFCeKeslJ6FBD-^dIUsFii6nyJj zq;u{zi}Po>T?6pbr-qt};%v-ZeVvjdb2Xdmxj6>?J?DFf!!>0SI_%Q&BU4eAlQ@fj zKcnQ?)IMwl<2k6sS>zJz&vUa7JB6LMRF zCKh~wAb$NrRwW5v;=j;JoZGlW?npDjO%B5}KoN zrocz43z29)%nUzN&Q5^`ei-+ZpK}K*aTyDk^b$k#^8XMqpz-eRxJg^OuAZ?aH^9F9 zTMHoV4g?R>l<4DMqtG^}P|};O84!uuEM=k+8^lhQ_s31(*Te0H^S~fH+OX@dDk^<$ zIp;~$sT%A+q1z)j&Kwnf0U|#=oUwghL%^1{@ZjOy00sdhkx(VIu?z;Dm_^vUmFkaK zsA&OQtOr|w9E%;?v&SOoiYa3CdnUpsv{V#SZJGPnEt`xa%uuOh_1;#zIWlf|@^woB z;~^`o|B>GqHBuT7GVHTv5u9Sl$u{Gq-0Oibqz0QewUE6z)=-G(I+kS0yXZnqR`i1o zRfOy|SrONJ&s5ZK9abA&J^y#;8{ux2$#+guPbG29nqf_>>@VyuZ!>B5402xi2L;?5TrJW&R92Qw-DC@!?`e9o##;Ac$3V_+VO7}0(H#asJEYO>%xEw7N;0u+B+l}$dM3*!n(Hyb1I=0|K`2TK2S zyXr(G?L^OVPc7{7!^W^HMI@Pc#|99g4e4=9!A&E*`6jr@D_e6qAjb9+{zfPBLxDjz zy`B+oHRw_(qfQbxm{+VT=(;)c0kb`!z<#;Du*;{)heC51@otsc@ABiaz`ADNO5T^? zbj5_+O0*>#r(n}HwH52lwCs>_(ARS6!1S`#iWGd||Ch%Cdypojdz zpn*3%J-s2y-sQFmDY4mM79QRrn^ym3@dIl5&xb8P&ND~*b&Zs`;fwqklCn=U+IbRu z?K?<@v;2x6m7KmMgO}^NP{gp;`S};oC>~5_yNlKaU z0JbK#GP*Mu;Lbb6&{^nyJ_b$Qj3n%*BIM@siQ;ajX!6wmi=zOnev^NXe8`?HMqsxy z=CcayXn3~Bb}!&)lGv0O)9Rj+shBB2uegrj zO+>AakZ(YVe75jD8uH$xMX7jOTUed9wMLI$^l`N=olpOG#)z{nW!1>aFPK-Sv@Ruw zx})$WeME3Rp-vP0GWO`gZKx6~(R-r8CnMFaBuik?p?{^;yWy`}MhyhjAoB8ILhoco z*mBY`<`CO1NtL}A7kTq-+$y2`n_M+a8Y=cMF)B@=Mxk^NT!~|dcFD7EGQPnS5!3Lq zj{S=dPgq6tXvAm$AkHVDv`G6SF}7X#OTA^j0enf1%iI9YwbB^=UNGtseA;%|?6&n( zKTGXgr6YvhFl#0RYjgiKq_H~3^adBnx@+^VSMwUnEcwVMDSN2{G`+0PvZ#yzA(!Cc zB1rne{H|`LuxO4F8|U$%qIk<~S=iE$MC4z-!k5J`rhsihfx@v;`OIEmB&^XQ{~*Jj z&;UUBSR~^0&7awOB-m3FW#`#WP}pUDmHFblv*VLNGRVXTw^G`pw?{QTj`U!OhB%ZtB;u4T)D5%tvxjKaU(z#>V7viw;c|l2_Y~;m zB}y1;)+(7f1P$fvOh@C^ZLfpb4(-HCv?+c(zGIs;dW7%0Nu&iRmDRYE zYaJ>7n?sd_{4(P*yS0pPZ@ri&pO1=g-{z#j%!*}G&@*@A>tJKZ@aqL!vrw)k(#Y`E z*$Y`MSieWes*p?XG_j3Zhr!fxD&TG29V>hErei0${lf#UzBW`$Lrbi(#71Y?EDXDl zHY`$zGH3IB7o-_)Rm&=HbCvFQj_PBlgJ;RN5Bp`GQAn~tjk>@aMxr#Gv+O^b-jfV| z!dSK7ZK?)agrKTgsZ7m0z^IB82%+A66UKERvCYKme2*$ zbU>v94x_t9Qd-?`<9_j2;|rSFk-;^G5>OB0E>+mK`}#r+FxR={_auI=t~$A^Ry*j5 z?MO^fxelkA>wF>Sda*-HA>KEFR-fXvE!NldfIGJ+W}1YK|B8ZJx-)1CY1v!KS5`-y zbdJm6cN$8MxJVG(vfuo;sK3ekZE_iua$bs8uk%6Hy|*;TwI)<$?>qhMWb9bk;F$y@ z;5Rjeu9W4QKtzvxoHLv?avtM^8t>Vc0M&OpGji6;#L#9qvJ$*`rl)2K9 z6K88id)BLL#zLOkWK<&q1yJ8y5R5d(dqrF)w=&Q25!!=4gSP_o>k=D8s55d6cK?;@ zJ^N|Lku)JZvSl^ITK{`~WJA#QkWW9ZAnA@tGn@Fq?LDYN<5^K=>uhc$LBHJvMn){3 zWdY^34FDX|t^pBu=rm}P$yxedX@W>^LN6~EFHaauFBso~9^GK;*t9&5QmM{)|Js}C zhp!9vJ|1Yr#bM3=EU2X?vV~#lin6!Mq@vUF-OtOS8;_(lS}1VaWt?_wuVj@X2(D$y zUiqb^rOJ(C8AP9a#z8Kft8R(#SJ8>$ekT3D`U4=k-;;hNY~nl3Ih?2kFgLxE%CRRC zOIBk7_k$Kp0e4=~Ox$1Tsb;-F|03T`AXl@%j6^woh#$*BA0yNktodCeMae_5v}+rM%wG;`44&zv|NkOgvj zc7(G}o)OtHhigqVC^l@uP;yTNd@`jK2o1dClW1@dnb+2JikG%W?$%4$g!sPPu@0|_ zQXwkv`(ya+s>8;)IG?>(lxO=*T;eW0#M@Uz%2KnAjfK8ka z8k{zZ72PLd$~OGF$7<1fSH%yj2&WgC{K-m_P2&!+g2ovTf89VDXF^3ikZ=hw?CVn55L zWXBht`&^Z`tHZyiaV_gu?k>~ldL?_pBf?VeHqT;XAR2|;3}nt7Ds@n$(*^Xj8#k@A zuC}(N&~Mi@yrkF+Ea0{d%sO;Q(pP=tZ*?&xYp5aLKP>k7FfYGahL_;6^nG-?cBwHl zOK<1(O>_@Sh*_6TVP(}bn&yl)2m#iVl#ajcX|#U5T1jEeDap;CjtFEr_p)SLg|-&c zfNIl0X8;PEQZK^b6MvmK^De}-caY}fqIy&1{i2ss7PjcsFBP+JTDi!nRazmX*90b8 zGn=4pD1lq6X*Ja(&ll%U6a0lL%|#ogQd;pnMt_bww_;jbK3b@STta*wUGf=RFI~y_ zn>HHcq_ZHLwmS0j+wH(sU`B`Vgfj!=>hC~ZRYmHr^38TBWROWf50Y?~V(|{NZMWSf zZ7ixN?AhT`@b5D3n7Pp4Tz!@`+{MK=VLS<2ix(L*D9^bo^>2OZ^El8io2I`ez&++6 zf{Kh6=#{jrM19jUC>#Xcv;;$;{(lATW&_?UL0~Y&#Y7`!;;Y}Nl2@(<6=A)o>{qgm zLf#S5*L6H7vt||?dtx5+C5G>Gj4p&s<3(X>2)WCJB8-y^$y-m688r(W_={+Zs$M57 z=YLMhV}2jCEpIC+C#uLxQQfYBwu%@*vKI1R{ShoKBH*Elf*oL*S{@OfdL2<36CeDg z5_e_m`e>Yh^+R5|QIAHJKm98tBz3(l(Wo!k{sCAn9B$;=<(Kyy&8*wOCA55{NoCTy zKFiCZdfXm4?6jWV3%MoBq*X~0Vd$|Ir8y6xT>HTj?24Q``w)r9+qc!)@VMG0=4qjg z+W_OFX~-V)(n3L51VMn9)71vP!Q)xS&7wJQF2xDy3lNt-9MK#c%HJ4kpAHm-ovzM2 zxqKtnKhC&U9SVVXqeD#Pza_L1)dV+?^tSufEB*^T9&UQ#TJ}?l%2JGZx9x1BO^s-e z=DmmGiz{r1nhG;`l3JgGcCC9Cf3@bITlC7-uxHg*3E%vRS2lPFL2WTO|4LB&>ru6f zxE&%>8Dhb)^vrfTLGI$WQIMpea579E3PEfd?sHeXuE!BAe926R-lDowtU_OFshl;Q zG~8G=XS0Now>f{H@d_#o8XU8`^v*Ij&^V5wNJKR{N>Ze=eox)KSo!XfCyI-ETb^~f z*b9#G?^yciLQ<=mD?&Hn@La1cTC0y>^#&2-u;rTOU_GdivieR}vhb|AQFl1?#f$wO z6pi#)n*dNcy26_aJ0Oadej^NRfSn4K-7b8!p<{UArk2!zVGJAV3QM4|eR- z9eVv_jvWQ@R0%f(u=Y?$Ey;asawkW~H%c9NV^KF&MKXLp>tF#~oJ&gK_fpq!l?T(v zfb-nW3-K#*9UDm6mL26mT8hhf!O@j7Dt6CW6WXKLq}C4y}A<~%T`WYX4WXU9$=fZ1Mr_bNGgeaavYK9W7-X1e{!X=5pLB*PBECbIN^ zGgNaEoE?Mm5SjG!DiY6{<4W4?9zJv19|0ne38$qFFoSbwW3lv-6b-sqg81ilE>D z-kmZ8&x8^}c0<*2b$p0sGPIu4tu7pj?tr)5Xyorots~}Y1)Jj*EY=deg+m=f2U_6} zIaF4fhn}k1o;c<&A_5##8<-xO`1eSU2r>r-Nz%EEMVp-ugg`vAaBp(Ha`jD%_L(ON zr>RhVKC9Qhl>uQNnRq)HvhCgpyhC#x^>X8WjaQ>PabZBm@i;G1P%PN-p?u1(kM%;> zHJ^lsIHi?P9kZsWVl$}XWksRU{`z*W?0SLT@NdJlRhV<%@!d-@K<13kp?3W#Y;Fvb z*I-STMN)S{OOf@7c9hIg)%blPiy?Ls`=aHuEPqXtT^CT7@o*+|Vsk%83@M{tgw_fK z)xBuC_;PcSuA$Nbe`?k2RrRsV2x12LPtbhw_DNNZdjCPI$3tNNQXdlC1 zB&tk3{ZOYoDv8XXtMwO=pP7$B=dQhgn5*6P>lueyR_}>SuiF}qQL|(FKPtk<&UJ!| z^DMn~1I2_scm3o_aAw}45VSwCinax~0g zT~Vry2GH;Pm>N>}#Ncy}BX_eJ#00}_7!bp~Y|}9D(o>l;y@q_8Y6$GZEpzZgpGn6w zTUy3QNLGw~%3{f2$d(|~+~;PmK2N`B#kURL44r0VO7QJ%y}(wh->o_w+nHe=DaI}2 zv;O0b1doKaz$?`aolzzO@tp1>WX!`@vLp_pzz>vTsX$hwVGpPKg|nEd%rrS1#Y(93 zx*p|mR2DrU6qIWV#fR@r`N2>!|5Ph@{@7da0F@=xyxd|inNqupWoO>@A#>e)G@QqQ zS_I;jkBU49yohNj$`4|7U|~o;&AcKfw!$h|xqs}JwCK69QA!S$a>(=cjsI9O)bezh zo)sF!j9>O>0(3pOi|*My7+Lf)JW;f6$YiCw0$(Rvf@2Kh@(3B|>%)yglq~lSs)YP%LgK2EPxmml-gP|8ueqNs%dPo~ zO+k@opHt=v17^!%l?;v2$-~brdnr;E2&HXpy4MoR^D(n?_mGJM|LmUK z1&PzzYG}z4(_51@X!n7%1B-_a(Q80XdsLI1QA-spQ`K92I#%@*w@iMOMpjSEm5$%?;|CeD zSxCF`O=%Am@c)bSn9|1$bdM72aF(&>h;EkW! zm_qATjM~Wa4}a0#DU8JiW_PZ@U2;2D`C-X{(7uFMZTm083wSfeWE$`O8-(s}p_j7j zr>TFZ6q2e!7+-X)>tF-9?!J;T-WtRF+?N>!-MI3GOZn-vEQYG)>u zdcGe@e&k{W$}BQPvrptReYY&k{{B_6s-9z#6qy?BO6)g+d& zG%#dM81P)wgqsT76E8Fo*01Y{*y77CQxHgTBS}mba9qj##S|n4O&Y$4s-{BOuaG*yJHXX5ZvfLQ}l;I8O^+f|m=YlAE^U$CoE zBiqH7dtE?^cNTQVu2=9r)|2$*)7Xi-bG2$3u{7S?y`Mq1f<3>JA>G6^fpwZvl&6h; z(uPtdPyO6)cW{MAM)UqQ4!uY`LZ+NeM9jy^e}z-9niAo`hZ{L(e7!8P(JJeQ%r?(f zVq}33WV6fW&C-93^Y`Tnddtly;#oRJ{&e#YfGSO3OY3=S1u2bEkm=4y(l@Uc(fUdI z?>Uh3AZQu=YV97;!X@!%Ja+uY6y6~H8rn49#-Hpf1nA=y=HWjRLzn3I`PZLQeq9&a z&NHs(Mk^L`HXL;R-;gloCDPiW&*F+rh<_)gxt3Jo{P)Bq&(2owj3HSOT`Vw$CmJ1<{BDTJK#_fNQJ;mW75{TrR&||MrM0@{ikY#Js4f@>IzM;qnWXVhD$)lL?ee z&j`{zni@i?ee7L~h;@tU0@x$Lomi#j+l~0C()meM2tE|vZrXGeTxR(gYXUgF?`Js=w@sYeH} zN^Z3CGYjqwG`2Tc3xtbgrsoJPV-V@ZS(a)T zoL(ri13@LDS@qGKF8~bZvav3X1EO0Ep`wwTsbl+wzw-330$k9MlI&=E7_p-{5%4ZO zF7A?vS{#UumKg__l58lPw}0p)5t>s`U6ckxI>%kP}Bw0E?E>XHi2jBW4Ecg zMBfx-=K{i(yqEQPYm!Qdv*0d$#IqEo&NZNOvVqw0CBHJ+U8tf$u?M;*gJtI7qH3cy z<$F@5c%|HG1$Vh3NVs4AYJ`#j5y?3gVmYnfnIALcEpt`Js#A4@V4w-`{qKB%;Li6v zfXL_`vhDC_L0CTW9bSI^TP$V!_Hk;_E_~)VXzT-Qu-wZ|X?1aPqVon3aC&2shj0J_ z^qR{s;fIIwQo~wjk!=E;wW8zG@tNUSlC4M^;NVch`R9!YCVyRcm_16TDtr~KVt7f9 zslRID^2K%7V+gbA)%Y7Xiw7f05cPJ7qq#dDFkw$5D)N&YpQfys+AX{hqo5UsHXK2I zHF)X!_cMfiWin)okbro3B8L6Y8%iLek-Xe(zAhJ#cc&K)wyVh1;R>dw+=HRq{7i z1?S<)_}HUaWi*sGdWxWDhufH&FO}&wwq1azT$-bw<3R#MNn}>vqC%niK?H0K71QoZ z94a1Jsk*=A5-h`|Tu(GhSVoCV{U3Dd5n9sjD_vBhlni#ZB5+)BZriL&i*>(A{v6$U}1fnkZ9cMW#kh9zUr3@H;PutM%^qY z48~agu;7u5hflrTV^>O8N-qNfjHXAu%_i%(V{LQQnQe-fHUFDcD9>QMMJ*R>$$UUL z{T}tYu=$)a(-eoCM}z-t9xP*t%!VX5?#E!dM#DM5bIzpj|SoH(CSa_N^W7M&%*zh4x$6R}RYM7`TR4F4Ae1db5 zk9^2CJyCy5NcZTV@l)_q33!iWXwcJKgf8JVYHZ;ZQW8rGVUf&Z;w!VMm8NLT-)$pm z)e7kP&OHYVP=$qvRFfnCxjgYJG{0g$sQ?Vu65G(fcfS2I-Vx$%f*m|k+$O(f7bv(2 zb8d|;-DSag=I#z}t0%X%bOPT7!>zP^-~q(T5!!_XwX8-lmfHBz)LQX zldG*3m2yLJCYo3TENRAA3Akbo*jhHmRr}h$P%CsYUqa{uZowy6?ijkc*~BGWz#K2! zAKXf$MgkLy)NgZhmCVbHjK6syZ}3*MLt=WlR$u0-FARsKvDvN0TEYveVOekDV=5%q zW8XGNe!|6jT3{^8v1_kO-uzI@bZ_Oh05sVNv$48Gs4uYby6>(~^hp>5ic#LL4%`ij zQ_%j9K7V$ZIo1H)6=63v9aWBdcu<}ZGwtmNCA0qWp+4aqil>EJ@Wx)FUju%3IU~i? zj$w3q_ZP`+u$ZiK5BH?;Kow6p~9ch(L+EXdnPj7m-I z{KQZjaHpt@Q^nSPuD`atZLZo|U8}ckIlkG;XD9Z$X;If>1?7DO>`#Kw=gMh&#f&yM z`wc_?(3B^`(aiQT%~0?unaF984@vwuston5Bi39ZdfJkT)0&dtkZ_A3EKCj*F>ijR z{1c}$%-=u(4_b*uS>g%|CxBi3t}lz`vwemybJpoX)&N{~;@;+YSZkO-uamqV=RUH!+1^9QE9CNec{)cXqHgVg2rQWz8V(-+FWjV0`};97uBd0Q^Ne{f7* zT_e3R6`{w^aZD|wdBdYM{5x!mdkePnYFgQ$Z`{T)J{l>S={+& zz+3mXq|dD3pox94qZ`WGrzGFEVc`!8icgOJf3eAP`u|<`JNMnte