Bug 12996

Summary: NIST import not working
Product: [Yocto Project Subprojects] Security Response Tool Reporter: Ross Burton <ross.burton>
Component: GeneralAssignee: David Reyna <david.reyna>
Status: RESOLVED FIXED QA Contact:
Severity: normal    
Priority: Medium    
Version: unspecified   
Target Milestone: ---   
Hardware: x86   
OS: Multiple   
Whiteboard:
OS type for building Yocto: --- Type of Regression: ---
Verified: Documentation change: No (bug/feature does not impact docs)

Description Ross Burton 2018-11-09 12:48:42 UTC
Daylight saving has resulted in the NIST parsing being too strict:

$ ./bin/srtool_nist.py -n --source="NIST 2018"
--file=data/nvdcve-1.0-2018.json --url-file=nvdcve-1.0-2018.json.gz
--url-meta=nvdcve-1.0-2018.meta
BEGINNING NIST UPDATES PLEASE WAIT ... this can take some time
DATABASE UPDATED FAILED ... time data
'lastModifiedDate:2018-11-08T03:06:21-05:00\r\n' does not match format
'lastModifiedDate:%Y-%m-%dT%H:%M:%S-04:00\r\n'
Comment 1 David Reyna 2018-11-09 20:59:25 UTC
Remove UTC offset to avoid timezone/day light savings errors.
Comment 2 Ross Burton 2018-11-12 11:29:36 UTC
$ ./bin/srtool_nist.py -n --source="NIST 2018" --file=data/nvdcve-1.0-2018.json --url-file=nvdcve-1.0-2018.json.gz --url-meta=nvdcve-1.0-2018.meta
BEGINNING NIST UPDATES PLEASE WAIT ... this can take some time
[  99]                 CVE-2018-9999
DATABASE UPDATE FINISHED
Comment 3 Ross Burton 2018-11-12 15:57:03 UTC
Just discovered this in the NIST description field for new CVEs:

ERROR(1):b'Traceback (most recent call last):
File "bin/srtool_nist.py", line 695, in <module>
    main(sys.argv[1:])
  File "bin/srtool_nist.py", line 643, in main
    fetch_cve(args.cve_detail,args.cve_file)
  File "bin/srtool_nist.py", line 594, in fetch_cve
    summary[\'cpe_list\'] += nist_scan_configuration_or(config, cve_name, 0)\n  File "bin/srtool_nist.py", line 606, in nist_scan_configuration_or
    for cpe in cpe_or_node[\'cpe\']:\nKeyError: \'cpe\''
Comment 4 David Reyna 2018-11-12 22:54:16 UTC
NIST is its wisdom has added or replaced the "cpe" sub-table with "cpe-match" in the 2018 tables. The 2015 sub-table still uses "cpe".

The updated code now accepts both table names when scanning CPE entries.
Comment 5 Ross Burton 2018-11-13 09:54:10 UTC
Confirmed fixed.