• security tracker vulnerable versions

    From Zuzej, Kerstin@21:1/5 to All on Mon Mar 21 14:10:01 2022
    Dear Debian Team,

    via the security-tracker Debian provides information about the vulnerable and fixed package versions.
    However, I wanted to ask if the named vulnerable version is the version where the vulnerability was first identified or if it is the lowest number of a vulnerable package.
    Example:
    https://security-tracker.debian.org/tracker/CVE-2022-0330
    buster

    4.19.208-1

    vulnerable

    fixed in 4.19.232-1

    Is the vulnerability from >= 4.19.208-1 and < 4.19.232-1
    Or is every version lower then the fixed version vulnerable (< 4.19.232-1)

    Thanks a lot.

    Kind regards.
    Kerstin Zuzej

    <html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
    <head>
    <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
    <meta name="Generator" content="Microsoft Word 15 (filtered medium)"> <style><!--
    /* Font Definitions */
    @font-face
    {font-family:"Cambria Math";
    panose-1:2 4 5 3 5 4 6 3 2 4;}
    @font-face
    {font-family:Calibri;
    panose-1:2 15 5 2 2 2 4 3 2 4;}
    /* Style Definitions */
    p.MsoNormal, li.MsoNormal, div.MsoNormal
    {margin:0cm;
    margin-bottom:.0001pt;
    font-size:11.0pt;
    font-family:"Calibri",sans-serif;
    mso-fareast-language:EN-US;}
    a:link, span.MsoHyperlink
    {mso-style-priority:99;
    color:blue;
    text-decoration:underline;}
    a:visited, span.MsoHyperlinkFollowed
    {mso-style-priority:99;
    color:purple;
    text-decoration:underline;}
    span.EmailStyle17
    {mso-style-type:personal-compose;
    font-family:"Calibri",sans-serif;
    color:windowtext;}
    span.red
    {mso-style-name:red;}
    .MsoChpDefault
    {mso-style-type:export-only;
    mso-fareast-language:EN-US;}
    @page WordSection1
    {size:612.0pt 792.0pt;
    margin:70.85pt 70.85pt 2.0cm 70.85pt;}
    div.WordSection1
    {page:WordSection1;}
    </style><!--[if gte mso 9]><xml>
    <o:shapedefaults v:ext="edit" spidmax="1026" />
    </xml><![endif]--><!--[if gte mso 9]><xml>
    <o:shapelayout v:ext="edit">
    <o:idmap v:ext="edit" data="1" />
    </o:shapelayout></xml><![endif]-->
    </head>
    <body lang="EN-GB" link="blue" vlink="purple">
    <div class="WordSection1">
    <p class="MsoNormal"><span lang="DE">Dear Debian Team,<o:p></o:p></span></p>
    <p class="MsoNormal"><span lang="DE"><o:p>&nbsp;</o:p></span></p>
    <p class="MsoNormal">via the security-tracker Debian provides information about the vulnerable and fixed package versions.<o:p></o:p></p>
    <p class="MsoNormal">However, I wanted to ask if the named vulnerable version is the version where the vulnerability was first identified or if it is the lowest number of a vulnerable package.<o:p></o:p></p>
    <p class="MsoNormal">Example:<o:p></o:p></p>
    <p class="MsoNormal"><a href="https://security-tracker.debian.org/tracker/CVE-2022-0330">https://security-tracker.debian.org/tracker/CVE-2022-0330</a><o:p></o:p></p>
    <table class="MsoNormalTable" border="0" cellpadding="0">
    <tbody>

    <td style="padding:.75pt .75pt .75pt .75pt">
    <p class="MsoNormal"><span style="mso-fareast-language:EN-GB">buster<o:p></o:p></span></p>
    </td>
    <td style="padding:.75pt .75pt .75pt .75pt">
    <p class="MsoNormal"><span style="mso-fareast-language:EN-GB">4.19.208-1<o:p></o:p></span></p>
    </td>
    <td style="padding:.75pt .75pt .75pt .75pt">
    <p class="MsoNormal"><span style="mso-fareast-language:EN-GB">vulnerable<o:p></o:p></span></p>
    </td>
    </tr>
    </tbody>
    </table>
    <p class="MsoNormal">fixed in 4.19.232-1<o:p></o:p></p>
    <p class="MsoNormal"><o:p>&nbsp;</o:p></p>
    <p class="MsoNormal">Is the vulnerability from &gt;= 4.19.208-1 and &lt; 4.19.232-1 <o:p>
    </o:p></p>
    <p class="MsoNormal">Or is every version lower then the fixed version vulnerable (&lt; 4.19.232-1)<o:p></o:p></p>
    <p class="MsoNormal"><o:p>&nbsp;</o:p></p>
    <p class="MsoNormal">Thanks a lot.<o:p></o:p></p>
    <p class="MsoNormal"><o:p>&nbsp;</o:p></p>
    <p class="MsoNormal">Kind regards.<o:p></o:p></p>
    <p class="MsoNormal">Kerstin Zuzej<o:p></o:p></p>
    </div>
    </body>
    </html>

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From Adrian Bunk@21:1/5 to Kerstin on Mon Mar 21 14:40:01 2022
    On Mon, Mar 21, 2022 at 12:33:46PM +0000, Zuzej, Kerstin wrote:
    Dear Debian Team,

    via the security-tracker Debian provides information about the vulnerable and fixed package versions.
    However, I wanted to ask if the named vulnerable version is the version where the vulnerability was first identified or if it is the lowest number of a vulnerable package.

    It shows the vulnerability status of the latest packages currently
    available in a supported Debian suite.

    Example:
    https://security-tracker.debian.org/tracker/CVE-2022-0330
    buster

    4.19.208-1

    vulnerable

    fixed in 4.19.232-1

    Is the vulnerability from >= 4.19.208-1 and < 4.19.232-1
    Or is every version lower then the fixed version vulnerable (< 4.19.232-1)
    ...

    This distinction is irrelevant for what is supported by Debian,
    and therefore not tracked in the Debian security tracker.

    Kind regards.
    Kerstin Zuzej

    cu
    Adrian

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)