An Empirical Study of Vulnerability Handling Times in CPython

Fuente: arXiv
Enregistré dans:
Détails bibliographiques
Auteur principal: Ruohonen, Jukka
Format: Preprint
Publié: 2024
Sujets:
Accès en ligne:
Tags: Ajouter un tag
Pas de tags, Soyez le premier à ajouter un tag!
_version_ 1866909621652815872
author Ruohonen, Jukka
author_facet Ruohonen, Jukka
contents The paper examines the handling times of software vulnerabilities in CPython, the reference implementation and interpreter for the today's likely most popular programming language, Python. The background comes from the so-called vulnerability life cycle analysis, the literature on bug fixing times, and the recent research on security of Python software. Based on regression analysis, the associated vulnerability fixing times can be explained very well merely by knowing who have reported the vulnerabilities. Severity, proof-of-concept code, commits made to a version control system, comments posted on a bug tracker, and references to other sources do not explain the vulnerability fixing times. With these results, the paper contributes to the recent effort to better understand security of the Python ecosystem.
format Preprint
id arxiv_https___arxiv_org_abs_2411_00447
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle An Empirical Study of Vulnerability Handling Times in CPython
Ruohonen, Jukka
Cryptography and Security
Software Engineering
The paper examines the handling times of software vulnerabilities in CPython, the reference implementation and interpreter for the today's likely most popular programming language, Python. The background comes from the so-called vulnerability life cycle analysis, the literature on bug fixing times, and the recent research on security of Python software. Based on regression analysis, the associated vulnerability fixing times can be explained very well merely by knowing who have reported the vulnerabilities. Severity, proof-of-concept code, commits made to a version control system, comments posted on a bug tracker, and references to other sources do not explain the vulnerability fixing times. With these results, the paper contributes to the recent effort to better understand security of the Python ecosystem.
title An Empirical Study of Vulnerability Handling Times in CPython
topic Cryptography and Security
Software Engineering
url https://arxiv.org/abs/2411.00447