]> code.ossystems Code Review - openembedded-core.git/commit
cve-update-db: Use NVD CPE data to populate PRODUCTS table
authorPierre Le Magourou <pierre.lemagourou@softbankrobotics.com>
Wed, 6 Nov 2019 15:37:35 +0000 (17:37 +0200)
committerRichard Purdie <richard.purdie@linuxfoundation.org>
Wed, 6 Nov 2019 20:44:15 +0000 (20:44 +0000)
commit6977d15fbc3b78958768b21f6c501e7d63be9499
treeb0f28eb5bf0a8bd0d7c26b96c89ba9eaca9daf19
parent075683d23018760e8b2fa0b793ceacd9027e55c3
cve-update-db: Use NVD CPE data to populate PRODUCTS table

Instead of using expanded list of affected versions that is not
reliable, use the 'cpe_match' node in the 'configurations' json node.

For cve-check to correctly match affected CVE, the sqlite database need to
contain operator_start, operator_end and the corresponding versions fields.

(From OE-Core rev: f7676e9a38d595564922e5f59acbc69c2109a78f)

Signed-off-by: Pierre Le Magourou <pierre.lemagourou@softbankrobotics.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
meta/recipes-core/meta/cve-update-db-native.bb