All of lore.kernel.org
 help / color / mirror / Atom feed
From: Gregory CLEMENT <gregory.clement@bootlin.com>
To: buildroot@busybox.net
Subject: [Buildroot] CVE analysis of the resiprocate package
Date: Fri, 11 Sep 2020 10:30:34 +0200	[thread overview]
Message-ID: <87wo10vhp1.fsf@BL-laptop> (raw)
In-Reply-To: <87zh5wvkvw.fsf@BL-laptop>

Hello,

> Hello Thomas,
>
>> Hello Ryan,
>>
>> +Gr?gory in Cc.
>>
>> On Wed, 9 Sep 2020 16:32:08 -0500
>> Ryan Barnett <ryan.barnett@collins.com> wrote:
>>
>>> It appears that there may be an issue with how the CVE scanning script
>>> is working with buildroot as it is detecting that there is a CVE
>>> vulnerability with resiprocate package when the version which is in
>>> buildroot 1.12.0 includes this CVE fix as described in the debian
>>> security tracker and in the nvd.nist.gov website:
>>> 
>>> https://nvd.nist.gov/vuln/detail/CVE-2017-9454
>>> 
>>> Does the automated script not handle the minor version such as "beta"
>>> or "alpha" which is present in some of the versions listed in the
>>> nvd.nist.gov website?
>>> 
>>> I'm not familiar with the scripts and don't have time to dig into it
>>> but I feel like there is something missing here as I don't believe the
>>> right fix to is put the IGNORE_CVE for this one in the package.
>>
>> Thanks for pointing the issue. It's precisely by having such reports
>> that we can progressively improve our CVE tooling.
[...]
>> So indeed, I guess the problem is that in
>> cpe:2.3:a:resiprocate:resiprocate:1.12.0:beta9:*:*:*:*:*:*, we don't
>> see the "beta9", and only "1.12.0".
>>
>> I'm not sure how to use that though. Ignore when the "minor" version is
>> not "*" ?
>>
>> Perhaps what we need to do is a run of pkg-stats on all packages/CVEs,
>> and see how many CVEs have non "*" minor versions. This will give us
>> some idea of the scope of the issue.
>>
>> Gr?gory, do you think you could have a look into this ?
>
> I am going to generate the list.
>

Among the 2412 packages there are 121 packages for which CVEs refer to
minor version.

Gregory


Gregory Clement, Bootlin
Embedded Linux and Kernel engineering
http://bootlin.com

  reply	other threads:[~2020-09-11  8:30 UTC|newest]

Thread overview: 7+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
     [not found] <20200907071032.C7EB26064C@crulimr02.rockwellcollins.com>
2020-09-09 21:32 ` [Buildroot] [autobuild.buildroot.net] Your daily results for 2020-09-06 Ryan Barnett
2020-09-09 21:57   ` [Buildroot] CVE analysis of the resiprocate package Thomas Petazzoni
2020-09-11  7:21     ` Gregory CLEMENT
2020-09-11  8:30       ` Gregory CLEMENT [this message]
2020-09-11  8:47         ` Thomas Petazzoni
2020-09-11  9:27           ` Gregory CLEMENT
2020-09-11  9:52             ` Gregory CLEMENT

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=87wo10vhp1.fsf@BL-laptop \
    --to=gregory.clement@bootlin.com \
    --cc=buildroot@busybox.net \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.