<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugzilla.yoctoproject.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.6"
          urlbase="https://bugzilla.yoctoproject.org/"
          
          maintainer="it-coreprojects-helpdesk@linuxfoundation.org"
>

    <bug>
          <bug_id>14127</bug_id>
          
          <creation_ts>2020-11-16 20:28:04 +0000</creation_ts>
          <short_desc>cve-check falsely indicates a vulnerabily to be patched</short_desc>
          <delta_ts>2023-03-31 07:33:31 +0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>7</classification_id>
          <classification>Build System, Metadata &amp; Runtime</classification>
          <product>OE-Core</product>
          <component>core</component>
          <version>3.2</version>
          <rep_platform>x86</rep_platform>
          <op_sys>arm64</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>Medium+</priority>
          <bug_severity>major</bug_severity>
          <target_milestone>4.2 M4</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Jere Viikari">jere.viikari</reporter>
          <assigned_to name="Geoffrey Giry">geoffrey.giry</assigned_to>
          <cc>chee.yang.lee</cc>
    
    <cc>geoffrey.giry</cc>
    
    <cc>jere.viikari</cc>
    
    <cc>meta.mr.watcher</cc>
    
    <cc>meta.watcher</cc>
    
    <cc>randy.macleod</cc>
    
    <cc>ross.burton</cc>
    
    <cc>sakib.sajal</cc>
    
    <cc>tim.orling</cc>
    
    <cc>yoann.congal</cc>
          
          
          <cf_os>---</cf_os>
          <cf_regression_type>---</cf_regression_type>
          
          <cf_docchange>No (bug/feature does not impact docs)</cf_docchange>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>88613</commentid>
    <comment_count>0</comment_count>
    <who name="Jere Viikari">jere.viikari</who>
    <bug_when>2020-11-16 20:28:04 +0000</bug_when>
    <thetext>It seems cve-check does not understand operator OR in JSON file&apos;s nodes field.

Example CVE-2020-15778 which not fixed in OpenSSH release 8.3p1 (maybe never).

CVE-check output:

PACKAGE NAME: openssh
PACKAGE VERSION: 8.3p1
CVE: CVE-2020-15778
CVE STATUS: Patched
CVE SUMMARY: scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omit validation of &quot;anomalous argument transfers&quot; because that could &quot;stand a great chance of breaking existing workflows.&quot;
CVSS v2 BASE SCORE: 6.8
CVSS v3 BASE SCORE: 7.8
VECTOR: NETWORK
MORE INFORMATION: https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-15778

$ wget https://nvd.nist.gov/feeds/json/cve/1.1/nvdcve-1.1-2020.json.gz

    &quot;configurations&quot; : {
      &quot;CVE_data_version&quot; : &quot;4.0&quot;,
      &quot;nodes&quot; : [ {
        &quot;operator&quot; : &quot;OR&quot;,
        &quot;cpe_match&quot; : [ {
          &quot;vulnerable&quot; : true,
          &quot;cpe23Uri&quot; : &quot;cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:*&quot;,
          &quot;versionEndExcluding&quot; : &quot;8.3&quot;
        }, {
          &quot;vulnerable&quot; : true,
          &quot;cpe23Uri&quot; : &quot;cpe:2.3:a:openbsd:openssh:8.3:-:*:*:*:*:*:*&quot;
        }, {
          &quot;vulnerable&quot; : true,
          &quot;cpe23Uri&quot; : &quot;cpe:2.3:a:openbsd:openssh:8.3:p1:*:*:*:*:*:*&quot;
        } ]
      } ]

Non-existing version 8.3 is excluded but 8.3p1 is vulnerable.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>93158</commentid>
    <comment_count>1</comment_count>
    <who name="Randy MacLeod">randy.macleod</who>
    <bug_when>2022-04-21 15:17:16 +0000</bug_when>
    <thetext>There may be a duplicate of this bug. Ross is going to check.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>93159</commentid>
    <comment_count>2</comment_count>
    <who name="Ross Burton">ross.burton</who>
    <bug_when>2022-04-21 15:20:43 +0000</bug_when>
    <thetext>Related to https://bugzilla.yoctoproject.org/show_bug.cgi?id=14630 as the CVE expression parser doesn&apos;t quite work right.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>95070</commentid>
    <comment_count>3</comment_count>
    <who name="Geoffrey Giry">geoffrey.giry</who>
    <bug_when>2023-03-07 10:37:07 +0000</bug_when>
    <thetext>When querying the CVE db used by cve_check, we can see that the name of the version stored in db is not the official release name : 

$ sqlite3 downloads/CVE_CHECK/nvdcve_1.1.db .dump | grep CVE-2020-15778
INSERT INTO NVD VALUES(&apos;CVE-2020-15778&apos;,&apos;** DISPUTED ** scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omit validation of &quot;anomalous argument transfers&quot; because that could &quot;stand a great chance of breaking existing workflows.&quot;&apos;,&apos;6.8&apos;,&apos;7.8&apos;,&apos;2023-02-24T19:43Z&apos;,&apos;NETWORK&apos;);
INSERT INTO PRODUCTS VALUES(&apos;CVE-2020-15778&apos;,&apos;openbsd&apos;,&apos;openssh&apos;,&apos;8.3_p1&apos;,&apos;=&apos;,&apos;&apos;,&apos;&apos;);
INSERT INTO PRODUCTS VALUES(&apos;CVE-2020-15778&apos;,&apos;openbsd&apos;,&apos;openssh&apos;,&apos;8.3&apos;,&apos;=&apos;,&apos;&apos;,&apos;&apos;);
INSERT INTO PRODUCTS VALUES(&apos;CVE-2020-15778&apos;,&apos;openbsd&apos;,&apos;openssh&apos;,&apos;&apos;,&apos;&apos;,&apos;8.3&apos;,&apos;&lt;&apos;);

The database use the name 8.3_p1, cve_check use 8.3p1.

I will propose the following patch:

Modify cve_check to interpret _ in the version name from the DB correctly:
* removed for updates (_p*).
* replaced by - for release candidate (_rc*)</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>95250</commentid>
    <comment_count>4</comment_count>
    <who name="Geoffrey Giry">geoffrey.giry</who>
    <bug_when>2023-03-31 07:33:31 +0000</bug_when>
    <thetext>Fixed by: https://git.yoctoproject.org/poky/commit/?id=81740facf458a5a3326c0cfca20ebf75d8fe91d0</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>