Re: debsecan e CVE
Davide Prina <[email protected]> Sun, 19 Oct 2025 10:20:23 +0200
| Newsgroups | gmane.linux.debian.user.italian |
|---|---|
| Message-ID | <trinity-bd845ed0-525c-4931-a8a0-b52c3ae5c82a-1760862023635@3c-app-mailcom-lxa04> |
Alessandro Baggi ha scritto:
> Su una Debian 12 ho installato debsecan con lo scopo di verificare quali
> vulnerabilità gli aggiornamenti disponibili andranno a correggere.
>
> Per fare questo lancio:
>
> # debsecan --suite bookworm --only-fixed
non è esattamente così. Potrebbe essere che un fix sia già disponibile, ma
che il pacchetto non sia ancora stato reso disponibile. Ti verrà indicato
come fixed.
Inoltre:
$ man debsecan
[...]
CAVEATS
Much like the official Debian security advisories, debsecan's vulnerability tracking is mostly based on
source packages. This can be confusing because tools like dpkg only display binary package names. There‐
fore, debsecan displays the more familiar binary package names. This has the unfortunate effect that all
binary packages (including packages containing only documentation, for example) are flagged as vulnerable,
and not only those packages which actually contain the vulnerable code.
If the correct --suite option is specified, debsecan may mark some packages as obsolete. This means that
the binary package in question has been removed from the archive. In this case, you need to update all the
packages depending on the obsolete package, and subsequently remove the obsolete package.
For certain architectures, build daemons may lag considerably. In such case, debsecan may incorrectly mark
a package as fixed, even if an update is not yet available in the Debian archive.
Note that debsecan version uses the --suite option only to determine the availability of corrected packages
and to detect obsolete packages. If you specify the wrong suite, only the information on available security
updates and obsolete packages is wrong, but the list of vulnerabilities is correct.
Mixing packages from different Debian releases is supported, as long as the packages still carry their offi‐
cial version numbers. Unknown package versions (from backported packages, for example) are compared to the
version in Debian unstable only, which may lead to incorrect reports.
[...]
> cosi ottengo la lista dei CVE per i pacchetti che hanno un aggiornamento
> disponibile. Ho notato però che non tutti i CVE sono riportati.
non so se questa cosa è ancora vera, ma un bel po' di tempo fa, se non
ricordo male, c'era il problema che l'aggiornamento di debsecan non era
in tempo reale e quindi ci poteva essere un piccolo disallineamento.
> Per esempio il pacchetto openssl, debsecan riporta:
[...]
> Ora il risultato finale è che debsecan riporta solo un CVE di quelli
> riportati nella mail DSA, il security tracker ne riporta 2. Noto che c'è
> una certa inconsistenza nelle info riportate.
puoi provare a chiedere, su questo punto non so aiutarti, oltre a quello
che ho scritto sopra.
Forse è meglio scrivere sulla lista debian-security (se ti iscrivi, la
lista ha un numero di messaggi, normalmente, abbastanza contenuto).
Ciao
Davide
--
La mia privacy non è affar tuo
https://noyb.eu/it
- You do not have my permission to use this email to train an AI -
If you use this to train your AI than you accept to distribute under AGPL
license >= 3.0 all the model trained, all the source you have used to
training your model and all the source of the program that use that model