# National Vulnerability database issues

**URL:** <https://discourse.julialang.org/t/national-vulnerability-database-issues/79938>\
**Category:** General Usage\
**Tags:** installation\
**Created:** [April 24, 2022, 11:29am UTC](https://discourse.julialang.org/t/national-vulnerability-database-issues/79938 "2022-04-24T11:29:16Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Allan\_Baker](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/allan_baker/32/42645_2.png) [@Allan\_Baker](https://discourse.julialang.org/u/Allan_Baker)\
**Post date:** [April 24, 2022, 11:29am UTC](https://discourse.julialang.org/t/national-vulnerability-database-issues/79938/1 "2022-04-24T11:29:16Z")

</div>

My Company uses an automated FOSS scanner that appears to track the national vulnerability database. I’ll have to dig around for more details. It complains about Julia’s full dependency packages found on [julialang.org](http://julialang.org) for things like gZip and others being vulnerable to exploitation. Is there a place where we can address these issues to make using Julia as free and open software an easier prospect?

---

<div class="post-metadata">

**Author:** ![Allan\_Baker](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/allan_baker/32/42645_2.png) [@Allan\_Baker](https://discourse.julialang.org/u/Allan_Baker)\
**Post date:** [April 24, 2022, 11:30am UTC](https://discourse.julialang.org/t/national-vulnerability-database-issues/79938/2 "2022-04-24T11:30:32Z")

</div>

[https://nvd.nist.gov/](https://nvd.nist.gov/)

---

<div class="post-metadata">

**Author:** ![goerch](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/goerch/32/29122_2.png) [@goerch](https://discourse.julialang.org/u/goerch)\
**Post date:** [April 24, 2022, 1:27pm UTC](https://discourse.julialang.org/t/national-vulnerability-database-issues/79938/3 "2022-04-24T13:27:31Z")

</div>

I searched [there](https://nvd.nist.gov/vuln/search/results?form_type=Advanced&results_type=overview&isCpeNameSearch=true&seach_type=all&query=cpe:2.3:a:julialang:julia:1.6.4:*:*:*:*:*:*:*) and didn’t find any CVE for 1.6.4 (the latest LTS version analyzed?).

Edit: [vaguely related](https://nvd.nist.gov/vuln/search/results?form_type=Basic&results_type=overview&query=julialang&search_type=all&isCpeNameSearch=false).

Another edit: do you have a recommendation how we can check this ourselves?

---

<div class="post-metadata">

**Author:** ![giordano](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/giordano/32/2166_2.png) [@giordano](https://discourse.julialang.org/u/giordano)\
**Post date:** [April 24, 2022, 2:15pm UTC](https://discourse.julialang.org/t/national-vulnerability-database-issues/79938/4 "2022-04-24T14:15:15Z")

</div>

> [@Allan\_Baker](#):
>
> It complains about Julia’s full dependency packages found on [julialang.org](http://julialang.org) for things like gZip and others being vulnerable to exploitation.

I’m not aware of the fact julia itself uses gZip (which I presume is [https://www.gnu.org/software/gzip/](https://www.gnu.org/software/gzip/)). Third-party packages may do.

---

<div class="post-metadata">

**Author:** ![Allan\_Baker](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/allan_baker/32/42645_2.png) [@Allan\_Baker](https://discourse.julialang.org/u/Allan_Baker)\
**Post date:** [April 24, 2022, 4:13pm UTC](https://discourse.julialang.org/t/national-vulnerability-database-issues/79938/5 "2022-04-24T16:13:47Z")

</div>

My bad. It wasn’t gzip. It was 7-zip.  
CVE-2008-6536 was the first one  
Cve-2016-2334 7zip  
Cve-2021-44732 - Mbed TLS  
Several more 7-zip

Cve-2019-17498 formlibssh2

Some for curl and the list continues.  
My scan was for Julia 1.7.2 with the dependencies

When I just did Julia without dependencies for 1.7.1 there were no issues.

This is a new area for me. Didn’t know if there was some way the release team could run these scans and weed out some of these issues instead of leaving it to the end user to really have no idea what to do.

Allan

---

<div class="post-metadata">

**Author:** ![Sukera](https://avatars.discourse-cdn.com/v4/letter/s/ce7236/32.png) [@Sukera](https://discourse.julialang.org/u/Sukera)\
**Post date:** [April 24, 2022, 7:08pm UTC](https://discourse.julialang.org/t/national-vulnerability-database-issues/79938/6 "2022-04-24T19:08:04Z")

</div>

Regarding 7zip, at least the recent version found on the master branch seems to download 16.02, which seems to be the most recent version. Libssh2 on master is using version 1.10, meaning it’s not vulnerable anymore to the specific CVE you posted (will have to check for LTS).

Do you have a link to the NVD NIST entry you’re referring to? How did you perform that scan?

Usually, if a patch is required, opening an issue on the repo ([GitHub - JuliaLang/julia: The Julia Programming Language](http://github.com/julialang/julia)) will lead to the patch to be applied for the next version.

---

<div class="post-metadata">

**Author:** ![Allan\_Baker](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/allan_baker/32/42645_2.png) [@Allan\_Baker](https://discourse.julialang.org/u/Allan_Baker)\
**Post date:** [April 26, 2022, 3:49pm UTC](https://discourse.julialang.org/t/national-vulnerability-database-issues/79938/7 "2022-04-26T15:49:38Z")

</div>

It looks like there is a patch directory:  
…\Downloads\julia-1.7.2-full (1).tar.gz\julia-1.7.2-full (1).tar\julia-1.7.2\deps\patches\

Does this mean that these changes are applied to the dependencies possibly mitigating some of the security concerns in CVE?
