cve-check tool does not detect all CVEs. Here come some examples: Ex1: bind has some CVE patches but these are not reported: ./recipes-connectivity/bind/bind/CVE-2016-2776.patch ? ./recipes-connectivity/bind/bind/CVE-2016-1286_2.patch ./recipes-connectivity/bind/bind/CVE-2016-1285.patch ./recipes-connectivity/bind/bind/CVE-2016-1286_1.patch ./recipes-connectivity/bind/bind/CVE-2016-2088.patch ./recipes-connectivity/bind/bind/CVE-2016-2775.patch How to reproduce: bitbake -c cve_check bind bitbake -k -c cve_check universe bitbake -k -c cve_check world No warning or cve.log file is created. These CVEs can be found in nvd.xml file (downloads/CVE_CHECK/nvdcve-2.0-2016.xml) <entry id="CVE-2016-2776"> ... cpe:/a:isc:bind:9.10.3" <<< is it because of cpe? ============================================================ Ex2: Some CVEs are marked in Mitre as "Reserved" of some unknown reason. ./recipes-core/busybox/busybox/CVE-2016-2147_2.patch <<< Reserved on Mitre: https://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2147 ./recipes-core/busybox/busybox/CVE-2016-2147.patch ./recipes-core/busybox/busybox/CVE-2016-2148.patch <<< https://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2148 We need to find a way to handle CVEs which are marked "Reserved" in Mitre. These CVEs are not present in nvd db (nvdcve-2.0-2016.xml) Some more example (curl CVEs) which are reported as "Reserved": https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-8615 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-8616 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-8617 .... ============================================================ Ex3:libcurl CVEs are not detected: libcurl is built when building curl, there is no recipes for libcurl. That is why libcurls CVEs are not detected and reported (e.g. cpe for CVE-2016-7141 is cpe:/a:haxx:libcurl): downloads/CVE_CHECK/nvdcve-2.0-2016.xml <entry id="CVE-2016-7141"> <vuln:vulnerable-configuration id="http://nvd.nist.gov/"> <cpe-lang:logical-test operator="OR" negate="false"> <cpe-lang:fact-ref name="cpe:/o:novell:leap:42.1"/> </cpe-lang:logical-test> </vuln:vulnerable-configuration> <vuln:vulnerable-configuration id="http://nvd.nist.gov/"> <cpe-lang:logical-test operator="OR" negate="false"> <cpe-lang:fact-ref name="cpe:/a:haxx:libcurl:7.50.1"/> <<<<<<<
Hi Mariano, Do you have any suggestion how to deal with issues found in nvd database? Do you think we should create a complement database or use other sources such as RedHat, Debian's database?
Unfortunately it seems cve-check-tool development has stopped, we need to check what other options do we have.
Moving to next release. As commented by Mariano, we need to review tool's current status.
you will never achieve this using just the NVD db. Many CVE # are listed with "Reserved" for years. To back fill that info, you need a team. This will never happen while we insist on Hash's as versions.
Marking as a dup of bug 11183 which is basically 'cve-check-tool isn't sufficient'. *** This bug has been marked as a duplicate of bug 11183 ***