Skip to main content

Read VEX files

Project description

vex-reader

OpenSSF Best Practices OpenSSF Scorecard GitHub release (latest SemVer) PyPI release Downloads

Utility to read Red Hat VEX files that are located at https://access.redhat.com/security/data/csaf/v2/vex/.

I'm (slowly) aiming to make this a bit more extensible so that it can be used with other VEX files beyond just Red Hat, but I'm basing all of this off of Red Hat VEX files to aim to make this a proper parsing library for any VEX documents.

Installation

Requires Python 3.10 or later.

Install vex-reader from PyPI:

pip install vex-reader

Or with uv:

uv pip install vex-reader

Usage

The best way to use vex-reader is to install the Python module. It provides the vex-reader binary and you can import the library for use in your own applications.

vex-reader --vex /path/to/advisory.json
CVE-2002-2443
-------------

Public on : 2002-06-15
Impact    : Moderate
CVSS Score: 5.0

Vulnerability summary
krb5: UDP ping-pong flaw in kpasswd


Vulnerability description
schpw.c in the kpasswd service in kadmind in MIT Kerberos 5 (aka krb5) before 1.11.3 does not properly validate UDP packets before
sending responses, which allows remote attackers to cause a denial of service (CPU and bandwidth consumption) via a forged packet that
triggers a communication loop, as demonstrated by krb_pingpong.nasl, a related issue to CVE-1999-0103.


CVSS score applicability
The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational
purposes to better understand the severity of this vulnerability.


Terms of Use
This content is licensed under the Creative Commons Attribution 4.0 International License
(https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide
attribution to Red Hat Inc. and provide a link to the original.


Additional Information
  Bugzilla: 962531

External References
  https://bugzilla.redhat.com/show_bug.cgi?id=962531
  https://www.cve.org/CVERecord?id=CVE-2002-2443
  https://nvd.nist.gov/vuln/detail/CVE-2002-2443

Red Hat affected packages and issued errata
  RHSA-2013:0942 -- Red Hat Enterprise Linux Workstation (v. 6)

CVSS v2 Vector
  Red Hat: AV:N/AC:L/Au:N/C:N/I:N/A:P
  NVD    : AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS v2 Score Breakdown
                           Red Hat    NVD
  CVSS v2 Base Score       5.0        5.0
  Access Vector            Network    Network
  Access Complexity        Low        Low
  Authentication           None       None
  Confidentiality Impact   None       None
  Integrity Impact         None       None
  Availability Impact      Partial    Partial

Copyright © Red Hat, Inc. All rights reserved

By default, vex-reader will pull the CVSS score from NVD's API. If this is undesirable (for testing, etc.) you can pass the --no-nvd argument to prevent lookups. Currently, vex-reader requires the VEX file to parse to be on-disk.

A good place to find VEX documents is https://wid.cert-bund.de/.well-known/csaf-aggregator/aggregator.json

License

GPLv3+. See LICENSE.

Contributing

Development setup, releasing, and Trusted Publishing notes: docs/DEVELOPMENT.md.

Running tests: docs/TESTING.md.

Security reports: SECURITY.md.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

vex_reader-0.9.5.1.tar.gz (55.7 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

vex_reader-0.9.5.1-py3-none-any.whl (43.0 kB view details)

Uploaded Python 3

File details

Details for the file vex_reader-0.9.5.1.tar.gz.

File metadata

  • Download URL: vex_reader-0.9.5.1.tar.gz
  • Upload date:
  • Size: 55.7 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.13

File hashes

Hashes for vex_reader-0.9.5.1.tar.gz
Algorithm Hash digest
SHA256 cd4a0fac9243e470b516e1687c7be0c09dac11351b27f5b3828d1af3b7c84559
MD5 1dbe4addc34e65fcc2fa5b16de0aeac4
BLAKE2b-256 068dda1bbc0505c6a8d743fa69aae62ff5c4ff45f3e0ffc502d48b7c08341669

See more details on using hashes here.

Provenance

The following attestation bundles were made for vex_reader-0.9.5.1.tar.gz:

Publisher: release.yml on vdanen/vex-reader

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file vex_reader-0.9.5.1-py3-none-any.whl.

File metadata

  • Download URL: vex_reader-0.9.5.1-py3-none-any.whl
  • Upload date:
  • Size: 43.0 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.13

File hashes

Hashes for vex_reader-0.9.5.1-py3-none-any.whl
Algorithm Hash digest
SHA256 3f641bfa68cc0bab7ea1b763d98c59c29d936f59d4bcfb606c013de43659f1b2
MD5 44045b21f99d267b0b00838da8d5c5d1
BLAKE2b-256 a3f0e892f4c85a314e28a9c353b2ddefdef24e8ad84118a83cea76c63f1b5c82

See more details on using hashes here.

Provenance

The following attestation bundles were made for vex_reader-0.9.5.1-py3-none-any.whl:

Publisher: release.yml on vdanen/vex-reader

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page