<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugzilla.yoctoproject.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.6"
          urlbase="https://bugzilla.yoctoproject.org/"
          
          maintainer="it-coreprojects-helpdesk@linuxfoundation.org"
>

    <bug>
          <bug_id>10771</bug_id>
          
          <creation_ts>2016-12-06 18:30:16 +0000</creation_ts>
          <short_desc>cve-check tool does not detect and report all relevant CVEs</short_desc>
          <delta_ts>2018-06-28 09:40:21 +0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>7</classification_id>
          <classification>Build System, Metadata &amp; Runtime</classification>
          <product>Security - Recipe Upgrade</product>
          <component>security</component>
          <version>unspecified</version>
          <rep_platform>x86</rep_platform>
          <op_sys>Multiple</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>DUPLICATE</resolution>
          <dup_id>11183</dup_id>
          <see_also>https://bugzilla.yoctoproject.org/show_bug.cgi?id=7515</see_also>
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>Medium</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>4.99</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Sona Sarmadi">sona.sarmadi</reporter>
          <assigned_to name="Ross Burton">ross.burton</assigned_to>
          <cc>akuster</cc>
    
    <cc>bluelightning</cc>
    
    <cc>ross.burton</cc>
          
          
          <cf_os>---</cf_os>
          <cf_regression_type>---</cf_regression_type>
          
          <cf_docchange>No (bug/feature does not impact docs)</cf_docchange>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>68878</commentid>
    <comment_count>0</comment_count>
    <who name="Sona Sarmadi">sona.sarmadi</who>
    <bug_when>2016-12-06 18:30:16 +0000</bug_when>
    <thetext>cve-check tool does not detect all CVEs. Here come some examples:

Ex1: bind has some CVE patches but these are not reported: 

./recipes-connectivity/bind/bind/CVE-2016-2776.patch ?
./recipes-connectivity/bind/bind/CVE-2016-1286_2.patch
./recipes-connectivity/bind/bind/CVE-2016-1285.patch
./recipes-connectivity/bind/bind/CVE-2016-1286_1.patch
./recipes-connectivity/bind/bind/CVE-2016-2088.patch
./recipes-connectivity/bind/bind/CVE-2016-2775.patch

How to reproduce:

bitbake -c cve_check bind
bitbake -k -c cve_check universe
bitbake -k -c cve_check world

No warning or cve.log file is created.

These CVEs can be found in nvd.xml file (downloads/CVE_CHECK/nvdcve-2.0-2016.xml)
 &lt;entry id=&quot;CVE-2016-2776&quot;&gt;
...
cpe:/a:isc:bind:9.10.3&quot; &lt;&lt;&lt; is it because of cpe?
============================================================
Ex2: Some CVEs are marked in Mitre as &quot;Reserved&quot; of some unknown reason.  
./recipes-core/busybox/busybox/CVE-2016-2147_2.patch  &lt;&lt;&lt; Reserved on Mitre: https://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2147
./recipes-core/busybox/busybox/CVE-2016-2147.patch
./recipes-core/busybox/busybox/CVE-2016-2148.patch &lt;&lt;&lt; https://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2148

We need to find a way to handle CVEs which are marked &quot;Reserved&quot; in Mitre. These CVEs are not present in nvd db (nvdcve-2.0-2016.xml)

Some more example (curl CVEs) which are reported as &quot;Reserved&quot;:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-8615
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-8616
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-8617
....

============================================================
Ex3:libcurl CVEs are not detected:
libcurl is built when building curl, there is no recipes for libcurl. That is why libcurls CVEs are not detected and reported (e.g. cpe for CVE-2016-7141 is cpe:/a:haxx:libcurl): 

downloads/CVE_CHECK/nvdcve-2.0-2016.xml

&lt;entry id=&quot;CVE-2016-7141&quot;&gt;
    &lt;vuln:vulnerable-configuration id=&quot;http://nvd.nist.gov/&quot;&gt;
      &lt;cpe-lang:logical-test operator=&quot;OR&quot; negate=&quot;false&quot;&gt;
        &lt;cpe-lang:fact-ref name=&quot;cpe:/o:novell:leap:42.1&quot;/&gt;
      &lt;/cpe-lang:logical-test&gt;
    &lt;/vuln:vulnerable-configuration&gt;
    &lt;vuln:vulnerable-configuration id=&quot;http://nvd.nist.gov/&quot;&gt;
      &lt;cpe-lang:logical-test operator=&quot;OR&quot; negate=&quot;false&quot;&gt;
        &lt;cpe-lang:fact-ref name=&quot;cpe:/a:haxx:libcurl:7.50.1&quot;/&gt;    &lt;&lt;&lt;&lt;&lt;&lt;&lt;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>70467</commentid>
    <comment_count>1</comment_count>
    <who name="Sona Sarmadi">sona.sarmadi</who>
    <bug_when>2017-02-07 08:40:24 +0000</bug_when>
    <thetext>Hi Mariano,

Do you have any suggestion how to deal with issues found in nvd database? Do you think we should create a complement database or use other sources such as RedHat, Debian&apos;s database?</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>71831</commentid>
    <comment_count>2</comment_count>
    <who name="Mariano Lopez">mariano.lopez</who>
    <bug_when>2017-03-28 20:47:12 +0000</bug_when>
    <thetext>Unfortunately it seems cve-check-tool development has stopped, we need to check what other options do we have.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>72474</commentid>
    <comment_count>3</comment_count>
    <who name="Leonardo Sandoval Gonzalez">leonardo.sandoval.gonzalez</who>
    <bug_when>2017-04-13 15:22:30 +0000</bug_when>
    <thetext>Moving to next release. As commented by Mariano, we need to review tool&apos;s current status.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>79545</commentid>
    <comment_count>4</comment_count>
    <who name="Armin Kuster">akuster</who>
    <bug_when>2018-02-22 04:04:22 +0000</bug_when>
    <thetext>you will never achieve this using just the NVD db. Many CVE # are listed with &quot;Reserved&quot; for years. To back fill that info, you need a team.

This will never happen while we insist on Hash&apos;s as versions.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>80953</commentid>
    <comment_count>5</comment_count>
    <who name="Ross Burton">ross.burton</who>
    <bug_when>2018-06-28 09:40:21 +0000</bug_when>
    <thetext>Marking as a dup of bug 11183 which is basically &apos;cve-check-tool isn&apos;t sufficient&apos;.

*** This bug has been marked as a duplicate of bug 11183 ***</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>