]> code.ossystems Code Review - openembedded-core.git/commit
cve-update-db-native: consider version suffix when update CVE db
authorLee Chee Yang <chee.yang.lee@intel.com>
Thu, 4 Mar 2021 14:44:06 +0000 (22:44 +0800)
committerAnuj Mittal <anuj.mittal@intel.com>
Fri, 9 Apr 2021 05:54:39 +0000 (13:54 +0800)
commitecb41c87695c483959e2d96fcb6ca7cd92fd7315
tree28645e2510135f5fa1997048810ea3c264134ea3
parentc28f771cdca01e419d869a797fe4d7520f2d810a
cve-update-db-native: consider version suffix when update CVE db

some record from NVD can merge or split suffix from version, for
example:
  CVE-2017-15906
  "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:5.0:p1:*:*:*:*:*:*"
  "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:4.7p1:*:*:*:*:*:*:*"

in such case include the suffix into version when update local CVE db.

Signed-off-by: Lee Chee Yang <chee.yang.lee@intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit 13cc68197f81bb7c76fa1abecc5dd720b8bdb8d5)
Signed-off-by: Anuj Mittal <anuj.mittal@intel.com>
meta/recipes-core/meta/cve-update-db-native.bb