Bug 10771 - cve-check tool does not detect and report all relevant CVEs
Summary: cve-check tool does not detect and report all relevant CVEs
Status: RESOLVED DUPLICATE of bug 11183
Alias: None
Product: Security - Recipe Upgrade
Classification: Build System, Metadata & Runtime
Component: security (show other bugs)
Version: unspecified
Hardware: x86 Multiple
: Medium normal
Target Milestone: 4.99
Assignee: Ross Burton
QA Contact:
URL:
Whiteboard:
Depends on:
Blocks:
 
Reported: 2016-12-06 18:30 UTC by Sona Sarmadi
Modified: 2018-06-28 09:40 UTC (History)
3 users (show)

See Also:
OS type for building Yocto: ---
Type of Regression: ---
Verified:
Documentation change: No (bug/feature does not impact docs)


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sona Sarmadi 2016-12-06 18:30:16 UTC
cve-check tool does not detect all CVEs. Here come some examples:

Ex1: bind has some CVE patches but these are not reported: 

./recipes-connectivity/bind/bind/CVE-2016-2776.patch ?
./recipes-connectivity/bind/bind/CVE-2016-1286_2.patch
./recipes-connectivity/bind/bind/CVE-2016-1285.patch
./recipes-connectivity/bind/bind/CVE-2016-1286_1.patch
./recipes-connectivity/bind/bind/CVE-2016-2088.patch
./recipes-connectivity/bind/bind/CVE-2016-2775.patch

How to reproduce:

bitbake -c cve_check bind
bitbake -k -c cve_check universe
bitbake -k -c cve_check world

No warning or cve.log file is created.

These CVEs can be found in nvd.xml file (downloads/CVE_CHECK/nvdcve-2.0-2016.xml)
 <entry id="CVE-2016-2776">
...
cpe:/a:isc:bind:9.10.3" <<< is it because of cpe?
============================================================
Ex2: Some CVEs are marked in Mitre as "Reserved" of some unknown reason.  
./recipes-core/busybox/busybox/CVE-2016-2147_2.patch  <<< Reserved on Mitre: https://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2147
./recipes-core/busybox/busybox/CVE-2016-2147.patch
./recipes-core/busybox/busybox/CVE-2016-2148.patch <<< https://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2148

We need to find a way to handle CVEs which are marked "Reserved" in Mitre. These CVEs are not present in nvd db (nvdcve-2.0-2016.xml)

Some more example (curl CVEs) which are reported as "Reserved":
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-8615
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-8616
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-8617
....

============================================================
Ex3:libcurl CVEs are not detected:
libcurl is built when building curl, there is no recipes for libcurl. That is why libcurls CVEs are not detected and reported (e.g. cpe for CVE-2016-7141 is cpe:/a:haxx:libcurl): 

downloads/CVE_CHECK/nvdcve-2.0-2016.xml

<entry id="CVE-2016-7141">
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/o:novell:leap:42.1"/>
      </cpe-lang:logical-test>
    </vuln:vulnerable-configuration>
    <vuln:vulnerable-configuration id="http://nvd.nist.gov/">
      <cpe-lang:logical-test operator="OR" negate="false">
        <cpe-lang:fact-ref name="cpe:/a:haxx:libcurl:7.50.1"/>    <<<<<<<
Comment 1 Sona Sarmadi 2017-02-07 08:40:24 UTC
Hi Mariano,

Do you have any suggestion how to deal with issues found in nvd database? Do you think we should create a complement database or use other sources such as RedHat, Debian's database?
Comment 2 Mariano Lopez 2017-03-28 20:47:12 UTC
Unfortunately it seems cve-check-tool development has stopped, we need to check what other options do we have.
Comment 3 Leonardo Sandoval Gonzalez 2017-04-13 15:22:30 UTC
Moving to next release. As commented by Mariano, we need to review tool's current status.
Comment 4 Armin Kuster 2018-02-22 04:04:22 UTC
you will never achieve this using just the NVD db. Many CVE # are listed with "Reserved" for years. To back fill that info, you need a team.

This will never happen while we insist on Hash's as versions.
Comment 5 Ross Burton 2018-06-28 09:40:21 UTC
Marking as a dup of bug 11183 which is basically 'cve-check-tool isn't sufficient'.

*** This bug has been marked as a duplicate of bug 11183 ***