| Summary: | cve-check tool does not detect and report all relevant CVEs | ||
|---|---|---|---|
| Product: | [Build System, Metadata & Runtime] Security - Recipe Upgrade | Reporter: | Sona Sarmadi <sona.sarmadi> |
| Component: | security | Assignee: | Ross Burton <ross.burton> |
| Status: | RESOLVED DUPLICATE | QA Contact: | |
| Severity: | normal | ||
| Priority: | Medium | CC: | akuster, bluelightning, ross.burton |
| Version: | unspecified | ||
| Target Milestone: | 4.99 | ||
| Hardware: | x86 | ||
| OS: | Multiple | ||
| See Also: | https://bugzilla.yoctoproject.org/show_bug.cgi?id=7515 | ||
| Whiteboard: | |||
| OS type for building Yocto: | --- | Type of Regression: | --- |
| Verified: | Documentation change: | No (bug/feature does not impact docs) | |
|
Description
Sona Sarmadi
2016-12-06 18:30:16 UTC
Hi Mariano, Do you have any suggestion how to deal with issues found in nvd database? Do you think we should create a complement database or use other sources such as RedHat, Debian's database? Unfortunately it seems cve-check-tool development has stopped, we need to check what other options do we have. Moving to next release. As commented by Mariano, we need to review tool's current status. you will never achieve this using just the NVD db. Many CVE # are listed with "Reserved" for years. To back fill that info, you need a team. This will never happen while we insist on Hash's as versions. |