Bug 8682 - Implement a way to check for vulnerable software on running target
Summary: Implement a way to check for vulnerable software on running target
Status: RESOLVED WORKSFORME
Alias: None
Product: Security - Recipe Upgrade
Classification: Build System, Metadata & Runtime
Component: security (show other bugs)
Version: unspecified
Hardware: x86 Multiple
: Medium enhancement
Target Milestone: Future
Assignee: New Comer Bugs
QA Contact:
URL:
Whiteboard:
Depends on:
Blocks:
 
Reported: 2015-11-11 22:37 UTC by Mariano Lopez
Modified: 2021-04-08 14:35 UTC (History)
3 users (show)

See Also:
OS type for building Yocto: ---
Type of Regression: ---
Verified:
Documentation change: Yes (doc changes required)


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Mariano Lopez 2015-11-11 22:37:23 UTC
When a target is deployed in the field, usually is never updated, not even for security fixes. What I'm proposing is to have a service in the target that checks the current packages and versions used, then compare with a list of vulnerable packages and versions; if the target is using a vulnerable software then notify the vendor/user. This won't automatically do the software update on the field but I think is a step in the right direction.
Comment 1 Saul Wold 2015-11-23 21:58:33 UTC
Also please review the existing meta-security layer which has some other 
runtime testing tools.
Comment 2 Armin Kuster 2018-02-22 04:00:25 UTC
there is a way of doing this. basically OVL files via openscap to run. this works. recipes in meta-security. Its generating the OVL files. This also creates html reports.
Comment 3 Randy MacLeod 2021-04-08 14:35:52 UTC
As Armin mentioned there is a solution in meta-security. There are other solutions provided by companies.