Bug 270547 - ports-mgmt/pkg: missing information about security vulnerabilities in system components
Summary: ports-mgmt/pkg: missing information about security vulnerabilities in system ...
Status: Open
Alias: None
Product: Ports & Packages
Classification: Unclassified
Component: Individual Port(s) (show other bugs)
Version: Latest
Hardware: Any Any
: --- Affects Many People
Assignee: freebsd-pkg (Nobody)
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2023-03-30 17:40 UTC by rashey
Modified: 2024-09-20 15:16 UTC (History)
7 users (show)

See Also:
bugzilla: maintainer-feedback? (pkg)


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description rashey 2023-03-30 17:40:23 UTC
# pkg audit -F FreeBSD-kernel-13.1_6
Fetching vuln.xml.xz: 100%  996 KiB   1.0MB/s    00:01
0 problem(s) in 0 installed package(s) found.

# pkg audit FreeBSD-13.1_6
0 problem(s) in 0 installed package(s) found.

There should be an information about CVE-2023-0286, CVE-2023-0215, CVE-2022-4450 and CVE-2022-4304 at least.
Also periodic security (405.pkg-base-audit) reports are incomplete because of the bug.

Reference:
https://www.freebsd.org/security/advisories/FreeBSD-SA-23:03.openssl.asc
Comment 1 Graham Perrin freebsd_committer freebsd_triage 2023-03-31 01:01:02 UTC
PkgBase, yes?
Comment 2 rashey 2023-03-31 04:15:49 UTC
No, why?
Comment 3 rashey 2023-03-31 18:45:54 UTC
The audit of both kernel and base is working regardless of PkgBase.

The last entries for both kernel and base are dated August 2022:
https://vuxml.freebsd.org/freebsd/pkg-FreeBSD-kernel.html
https://vuxml.freebsd.org/freebsd/pkg-FreeBSD.html
Comment 4 Miroslav Lachman 2023-05-04 20:05:47 UTC
(In reply to Graham Perrin from comment #1)
pkg audit works for base (kernel + world) for more than 6 years. It was originally created by Mark Felder. Then I created a port for periodic script https://www.freshports.org/security/base-audit/ which is now deleted as this functionality is included in pkg for about year.
https://lists.freebsd.org/pipermail/freebsd-security/2016-August/009049.html

But Security Officer Team must publish SAs to VuXML. It will not work without entries in database.
I think this PR should be assigned to Security Team, because maintainer of ports-mgmt/pkg cannot do anything about it.
Comment 5 SimpleRezo 2023-06-28 16:44:16 UTC
This should be fixed, because without it periodic output is not very revelant about security risks...
Comment 6 Dan Langille freebsd_committer freebsd_triage 2023-07-13 17:32:20 UTC
It the concerns first appeared in 2019:

https://forums.freebsd.org/threads/pkg-audit-vuln-xml-no-more-updates-for-base-system-and-kernel.71239/
Comment 7 Dan Langille freebsd_committer freebsd_triage 2023-07-13 17:32:58 UTC
*It seems

Sorry, I typed that comment and didn't mean to add it.
Comment 8 SimpleRezo 2023-07-19 10:25:43 UTC
I'm suggesting updating this PR:
  "Product" => "Security"
  "Component" => "Base System"
And maybe "Assignee" too.
Comment 9 Kirill 2024-09-20 13:45:53 UTC
Vulnerabilities 2024-09-19 are also missed.
Comment 10 Miroslav Lachman 2024-09-20 15:16:01 UTC
I still don't understand internal processes of publishing new SA. How is it even possible that records are so often missing in VuXML?