]> code.ossystems Code Review - openembedded-core.git/commit
cve-update-db-native: consider version suffix when update CVE db
authorLee Chee Yang <chee.yang.lee@intel.com>
Thu, 4 Mar 2021 14:44:06 +0000 (22:44 +0800)
committerSteve Sakoman <steve@sakoman.com>
Wed, 24 Mar 2021 14:30:32 +0000 (04:30 -1000)
commitb8d3e1754faea3ba0b6e07d5a830fbab12b5f53d
tree2629c9e62a96b2e4e8a50cacf92455ad7b3c96a0
parent3be53035c567c06a09a36d68c41393482bd4789b
cve-update-db-native: consider version suffix when update CVE db

some record from NVD can merge or split suffix from version, for
example:
  CVE-2017-15906
  "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:5.0:p1:*:*:*:*:*:*"
  "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:4.7p1:*:*:*:*:*:*:*"

in such case include the suffix into version when update local CVE db.

Signed-off-by: Lee Chee Yang <chee.yang.lee@intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit 13cc68197f81bb7c76fa1abecc5dd720b8bdb8d5)
Signed-off-by: Steve Sakoman <steve@sakoman.com>
meta/recipes-core/meta/cve-update-db-native.bb