V-SZZ: Automatic Identification of Version Ranges Affected by CVE Vulnerabilities
Lingfeng Bao, Xin Xia, Ahmed E. Hassan, Xiaohu Yang
Abstract
Vulnerabilities publicly disclosed in the National Vulnerability Database (NVD) are assigned with CVE (Common Vulnerabilities and Exposures) IDs and associated with specific software versions. Many organizations, including IT companies and government, heavily rely on the disclosed vulnerabilities in NVD to mitigate their security risks. Once a software is claimed as vulnerable by NVD, these organizations would examine the presence of the vulnerable versions of the software and assess the impact on themselves. However, the version information about vulnerable software in NVD is not always reliable. Nguyen et al. find that the version information of many CVE vulnerabilities is spurious and propose an approach based on the original SZZ algorithm (i.e., an approach to identify bug-introducing commits) to assess the software versions affected by CVE vulnerabilities. However, SZZ algorithms are designed for common bugs, while vulnerabilities and bugs are different. Many bugs are introduced by a recent bug-fixing commit, but vulnerabilities are usually introduced in their initial versions. Thus, the current SZZ algorithms often fail to identify the inducing commits for vulnerabilities. Therefore, in this study, we propose an approach based on an improved SZZ algorithm to refine software versions affected by CVE vulnerabilities. Our proposed SZZ algorithm leverages the line mapping algorithms to identify the earliest commit that modified the vulnerable lines, and then considers these commits to be the vulnerability-inducing commits, as opposed to the previous SZZ algorithms that assume the commits that last modified the buggy lines as the inducing commits. To evaluate our proposed approach, we manually annotate the true inducing commits and verify the vulnerable versions for 172 CVE vulnerabilities with fixing commits from two publicly available datasets with five C/C++ and 41 Java projects, respectively.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 952ae8b6-0cb0-4305-9b00-a89969624ca1Cited by top-tier papers18
- CHRONOS: Time-Aware Zero-Shot Identification of Libraries from Vulnerability ReportsYunbo Lyu, Thanh Le-Cong, Hong Jin Kang, Ratnadira Widyasari et al.ICSE 2023 · 20 citations
- Neural SZZ AlgorithmLingxiao Tang, Lingfeng Bao, Xin Xia, Zhongdong HuangASE 2023 · 9 citations
- Identifying Affected Libraries and Their Ecosystems for Open Source Software VulnerabilitiesSusheng Wu, Wenyan Song, Kaifeng Huang, Bihuan Chen et al.ICSE 2024 · 9 citations
- SymBisect: Accurate Bisection for Fuzzer-Exposed VulnerabilitiesZheng Zhang, Yu Hao, Weiteng Chen, Xiaochen Zou et al.USENIX Security 2024 · 7 citations
- Precise (Un)Affected Version Analysis for Web VulnerabilitiesYoukun Shi, Yuan Zhang, Tianhan Luo, Xiangyu Mao et al.ASE 2022 · 7 citations
Builds on6
- A Large-Scale Empirical Study of Security PatchesFrank Li, Vern PaxsonCCS 2017 · 273 citations
- Talos: Neutralizing Vulnerabilities with Security Workarounds for Rapid ResponseZhen Huang, Mariana D'Angelo, Dhaval Miyani, David LieS&P 2016 · 59 citations
- A large-scale empirical study on vulnerability distribution within projects and the lessons learnedBingchang Liu, Guozhu Meng, Wei Zou, Qi Gong et al.ICSE 2020 · 43 citations
- Evaluating SZZ Implementations Through a Developer-informed OracleGiovanni Rosa, Luca Pascarella, Simone Scalabrino, Rosalia Tufano et al.ICSE 2021 · 42 citations
- A Differential Testing Approach for Evaluating Abstract Syntax Tree Mapping AlgorithmsYuanrui Fan, Xin Xia, David Lo, Ahmed E. Hassan et al.ICSE 2021 · 18 citations
Related papers
- V0Finder: Discovering the Correct Origin of Publicly Reported Software VulnerabilitiesSeunghoon Woo, Dongwook Lee, Sunghan Park, Heejo Lee et al.USENIX Security 2021 · 36 citations
- Accurate Identification of the Vulnerability-Introducing Commit based on Differential Analysis of Patching PatternsQixuan Guo, Yongzhong HeNDSS 2026 · 1 citation
- Vulnerability-Affected Versions Identification: How Far Are We?Xingchu Chen, Chengwei Liu, Jialun Cao, Yang Xiao et al.ASE 2025 · 3 citations
- Locating the Security Patches for Disclosed OSS Vulnerabilities with Vulnerability-Commit Correlation RankingXin Tan, Yuan Zhang, Chenyuan Mi, Jiajun Cao et al.CCS 2021 · 43 citations
- Towards the Detection of Inconsistencies in Public Security Vulnerability ReportsYing Dong, Wenbo Guo, Yueqi Chen, Xinyu Xing et al.USENIX Security 2019 · 149 citations
