Openembedded Core Discussions
 help / color / mirror / Atom feed
* About the judgment result of the CVE check tool
@ 2022-12-02  9:55 Shinji Matsunaga (Fujitsu)
  2022-12-02 10:06 ` [OE-core] " Mikko Rapeli
  2022-12-02 10:09 ` Mikko Rapeli
  0 siblings, 2 replies; 3+ messages in thread
From: Shinji Matsunaga (Fujitsu) @ 2022-12-02  9:55 UTC (permalink / raw)
  To: 'openembedded-core@lists.openembedded.org'

[-- Attachment #1: Type: text/plain, Size: 1064 bytes --]

Hi, I'm Shinji.

I have a question about the judgment result of the CVE check tool.

If the version of the package "pv" cannot be compared to the version retrieved from NVD("version_start" or "version_end"),
there is a vulnerability for which the judgment result is "Patched".(e.g. CVE-2020-15117)

If you can't compare versions, I think it should be judged as "Unpatched"
Why does the CVE check tool judge "Patched"?

Examples of judgment results:

 LAYER: meta-qti-base-prop
 PACKAGE NAME: synergy
 PACKAGE VERSION: git
 CVE: CVE-2020-15117
 CVE STATUS: Patched

Examples of logs:

"WARNING: synergy: Failed to compare git < 1.12.0 for CVE-2020-15117"

log output location:

 https://github.com/openembedded/openembedded-core/blob/master/meta/classes/cve-check.bbclass#L346


富士通(株) ISS事本
Linuxソフトウェア事業部 アプライアンス技術部
松永 慎司 / Matsunaga Shinji
e-mail:shin.matsunaga@fujitsu.com<mailto:shin.matsunaga@fujitsu.com>


[-- Attachment #2: Type: text/html, Size: 6396 bytes --]

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2022-12-02 10:09 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2022-12-02  9:55 About the judgment result of the CVE check tool Shinji Matsunaga (Fujitsu)
2022-12-02 10:06 ` [OE-core] " Mikko Rapeli
2022-12-02 10:09 ` Mikko Rapeli

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox