Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Does Vuls match oval and 3rd party repositories? #1620

Open
MalfuncEddie opened this issue Mar 15, 2023 · 3 comments
Open

Does Vuls match oval and 3rd party repositories? #1620

MalfuncEddie opened this issue Mar 15, 2023 · 3 comments
Labels

Comments

@MalfuncEddie
Copy link

Hi,

For "reasons" we use the apache of "deb http://ppa.launchpad.net/ondrej/apache2/ubuntu focal main"
instead of the normal ubuntu one.

I was wondering if vuls also detects CVE's on those packages.

ii apache2 2.4.55-1+ubuntu20.04.1+deb.sury.org+2 amd64 Apache HTTP Server

should match cve https://ubuntu.com/security/CVE-2023-25690 but it doesn't?

@MaineK00n
Copy link
Collaborator

MaineK00n commented Mar 15, 2023

Currently, Debian/Ubuntu does not look at repositories of installed packages.

fixed version: 2.4.41-4ubuntu3.14 < installed version: 2.4.55-1+ubuntu20.04.1+deb.sury.org+2, so this should be treated as a unaffected vulnerability on your machine.

@MalfuncEddie
Copy link
Author

I'm a bit confused

Some mod_proxy configurations on Apache HTTP Server versions 2.4.0 through 2.4.55

also the the repo has an update 2.4.56 so I thought that 2.4.55 is also affected.

@MaineK00n
Copy link
Collaborator

I think 2.4.56 is the version of apache/httpd.
Please note that the versions of apache/httpd and the apache package provided by ubuntu do not always match.

I assume your machine is Ubuntu 20.04, but according to https://ubuntu.com/security/CVE-2023-25690 it is fixed in 2.4.41-4ubuntu3.14.
This is also described in launchpad's apache.
https://launchpad.net/ubuntu/+source/apache2/2.4.41-4ubuntu3.14

However, since you are not using apache in the official repository provided by Ubuntu to begin with, there is no point in looking at ubuntu's fixed version.
You should check what version of apache you are using, what version of apache/httpd you derived it from, and what patches you have applied so far.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

2 participants