Bug 191985 - x11/nvidia-driver-96 : not vulnerable but false positive in vuxml
Summary: x11/nvidia-driver-96 : not vulnerable but false positive in vuxml
Status: Closed Overcome By Events
Alias: None
Product: Ports & Packages
Classification: Unclassified
Component: Individual Port(s) (show other bugs)
Version: Latest
Hardware: Any Any
: --- Affects Only Me
Assignee: Alexey Dokuchaev
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2014-07-20 14:14 UTC by Rene Ladan
Modified: 2015-03-03 16:32 UTC (History)
1 user (show)

See Also:


Attachments
patch to fix vuxml entry for nvidia-driver-96 (533 bytes, application/x-download)
2014-07-20 14:14 UTC, Rene Ladan
no flags Details

Note You need to log in before you can comment on or make changes to this bug.
Description Rene Ladan freebsd_committer freebsd_triage 2014-07-20 14:14:32 UTC
Created attachment 144815 [details]
patch to fix vuxml entry for nvidia-driver-96

x11/nvidia-driver-96 shows up as vulnerable in vuxml, but both CVE-2012-0946 and CVE-2012-4225 have been fixed in the port.

Adjust vuxml accordingly.
Comment 1 John Marino freebsd_committer freebsd_triage 2014-07-20 14:20:12 UTC
over to maintainer
Comment 2 Alexey Dokuchaev freebsd_committer freebsd_triage 2014-11-16 15:07:48 UTC
The patch is correct, however, it is correct for the pre-pkgng world where several package versions could share the same package name (with default pointed by LATEST_LINK).

Since those times, all nvidia-driver legacy ports have different (ugly due to XX-XX doubling) names now, so that vulnerability check does not cover them at all:

$ pkg audit nvidia-driver-96-96.43.23_2
0 problem(s) in the installed packages found.

# Before (pre-pkgng, latest-link times):

$ pkg audit nvidia-driver-96.43.23_2
nvidia-driver-96.43.23_2 is vulnerable:
NVIDIA UNIX driver -- access to arbitrary system memory
CVE: CVE-2012-4225
CVE: CVE-2012-0946
WWW: http://portaudit.FreeBSD.org/b91234e7-9a8b-11e1-b666-001636d274f3.html

1 problem(s) in the installed packages found.

Shall I refactor vuln.xml to split original "umbrella" nvidia-driver entries covering all versions into per-port ones?  Shall I retain old entries or remove them (technically they are from EOL'ed pkg_* tools times, but users still might live with them after pkg2ng conversion).
Comment 3 Bartek Rutkowski freebsd_committer freebsd_triage 2015-03-03 16:32:45 UTC
The x11/nvidia-driver-96 port has been removed on 2014-12-19 with comment of 'Removed: Not compatible with xserver 1.14', closing the PR.