| Summary: | cve-check falsely indicates a vulnerabily to be patched | ||
|---|---|---|---|
| Product: | [Build System, Metadata & Runtime] OE-Core | Reporter: | Jere Viikari <jere.viikari> |
| Component: | core | Assignee: | Geoffrey Giry <geoffrey.giry> |
| Status: | RESOLVED FIXED | QA Contact: | |
| Severity: | major | ||
| Priority: | Medium+ | CC: | chee.yang.lee, geoffrey.giry, jere.viikari, meta.mr.watcher, meta.watcher, randy.macleod, ross.burton, sakib.sajal, tim.orling, yoann.congal |
| Version: | 3.2 | ||
| Target Milestone: | 4.2 M4 | ||
| Hardware: | x86 | ||
| OS: | arm64 | ||
| Whiteboard: | |||
| OS type for building Yocto: | --- | Type of Regression: | --- |
| Verified: | Documentation change: | No (bug/feature does not impact docs) | |
|
Description
Jere Viikari
2020-11-16 20:28:04 UTC
There may be a duplicate of this bug. Ross is going to check. Related to https://bugzilla.yoctoproject.org/show_bug.cgi?id=14630 as the CVE expression parser doesn't quite work right. When querying the CVE db used by cve_check, we can see that the name of the version stored in db is not the official release name :
$ sqlite3 downloads/CVE_CHECK/nvdcve_1.1.db .dump | grep CVE-2020-15778
INSERT INTO NVD VALUES('CVE-2020-15778','** DISPUTED ** scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omit validation of "anomalous argument transfers" because that could "stand a great chance of breaking existing workflows."','6.8','7.8','2023-02-24T19:43Z','NETWORK');
INSERT INTO PRODUCTS VALUES('CVE-2020-15778','openbsd','openssh','8.3_p1','=','','');
INSERT INTO PRODUCTS VALUES('CVE-2020-15778','openbsd','openssh','8.3','=','','');
INSERT INTO PRODUCTS VALUES('CVE-2020-15778','openbsd','openssh','','','8.3','<');
The database use the name 8.3_p1, cve_check use 8.3p1.
I will propose the following patch:
Modify cve_check to interpret _ in the version name from the DB correctly:
* removed for updates (_p*).
* replaced by - for release candidate (_rc*)
|