Bug 14127 - cve-check falsely indicates a vulnerabily to be patched
Summary: cve-check falsely indicates a vulnerabily to be patched
Status: RESOLVED FIXED
Alias: None
Product: OE-Core
Classification: Build System, Metadata & Runtime
Component: core (show other bugs)
Version: 3.2
Hardware: x86 arm64
: Medium+ major
Target Milestone: 4.2 M4
Assignee: Geoffrey Giry
QA Contact:
URL:
Whiteboard:
Depends on:
Blocks:
 
Reported: 2020-11-16 20:28 UTC by Jere Viikari
Modified: 2023-03-31 07:33 UTC (History)
10 users (show)

See Also:
OS type for building Yocto: ---
Type of Regression: ---
Verified:
Documentation change: No (bug/feature does not impact docs)


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Jere Viikari 2020-11-16 20:28:04 UTC
It seems cve-check does not understand operator OR in JSON file's nodes field.

Example CVE-2020-15778 which not fixed in OpenSSH release 8.3p1 (maybe never).

CVE-check output:

PACKAGE NAME: openssh
PACKAGE VERSION: 8.3p1
CVE: CVE-2020-15778
CVE STATUS: Patched
CVE SUMMARY: scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omit validation of "anomalous argument transfers" because that could "stand a great chance of breaking existing workflows."
CVSS v2 BASE SCORE: 6.8
CVSS v3 BASE SCORE: 7.8
VECTOR: NETWORK
MORE INFORMATION: https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-15778

$ wget https://nvd.nist.gov/feeds/json/cve/1.1/nvdcve-1.1-2020.json.gz

    "configurations" : {
      "CVE_data_version" : "4.0",
      "nodes" : [ {
        "operator" : "OR",
        "cpe_match" : [ {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:*",
          "versionEndExcluding" : "8.3"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:8.3:-:*:*:*:*:*:*"
        }, {
          "vulnerable" : true,
          "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:8.3:p1:*:*:*:*:*:*"
        } ]
      } ]

Non-existing version 8.3 is excluded but 8.3p1 is vulnerable.
Comment 1 Randy MacLeod 2022-04-21 15:17:16 UTC
There may be a duplicate of this bug. Ross is going to check.
Comment 2 Ross Burton 2022-04-21 15:20:43 UTC
Related to https://bugzilla.yoctoproject.org/show_bug.cgi?id=14630 as the CVE expression parser doesn't quite work right.
Comment 3 Geoffrey Giry 2023-03-07 10:37:07 UTC
When querying the CVE db used by cve_check, we can see that the name of the version stored in db is not the official release name : 

$ sqlite3 downloads/CVE_CHECK/nvdcve_1.1.db .dump | grep CVE-2020-15778
INSERT INTO NVD VALUES('CVE-2020-15778','** DISPUTED ** scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omit validation of "anomalous argument transfers" because that could "stand a great chance of breaking existing workflows."','6.8','7.8','2023-02-24T19:43Z','NETWORK');
INSERT INTO PRODUCTS VALUES('CVE-2020-15778','openbsd','openssh','8.3_p1','=','','');
INSERT INTO PRODUCTS VALUES('CVE-2020-15778','openbsd','openssh','8.3','=','','');
INSERT INTO PRODUCTS VALUES('CVE-2020-15778','openbsd','openssh','','','8.3','<');

The database use the name 8.3_p1, cve_check use 8.3p1.

I will propose the following patch:

Modify cve_check to interpret _ in the version name from the DB correctly:
* removed for updates (_p*).
* replaced by - for release candidate (_rc*)