Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #243431 > unrolled thread

How to see the list of CRITICALLY vulnerable packages in Debian?

Started bymaxwillb <maxwillb@mailfence.com>
First post2021-12-25 00:20 +0100
Last post2021-12-25 18:50 +0100
Articles 17 — 5 participants

Back to article view | Back to linux.debian.user


Contents

  How to see the list of CRITICALLY vulnerable packages in Debian? maxwillb  <maxwillb@mailfence.com> - 2021-12-25 00:20 +0100
    Re: How to see the list of CRITICALLY vulnerable packages in Debian? Dan Ritter <dsr@randomstring.org> - 2021-12-25 13:50 +0100
      Re: How to see the list of CRITICALLY vulnerable packages in  Debian? maxwillb  <maxwillb@mailfence.com> - 2021-12-25 17:20 +0100
    Re: How to see the list of CRITICALLY vulnerable packages in Debian? "Andrew M.A. Cater" <amacater@einval.com> - 2021-12-25 14:00 +0100
      Re: How to see the list of CRITICALLY vulnerable packages in  Debian? maxwillb  <maxwillb@mailfence.com> - 2021-12-25 15:40 +0100
        Re: How to see the list of CRITICALLY vulnerable packages in  Debian? maxwillb  <maxwillb@mailfence.com> - 2021-12-26 00:00 +0100
          Re: How to see the list of CRITICALLY vulnerable packages in Debian? "Andrew M.A. Cater" <amacater@einval.com> - 2021-12-26 13:10 +0100
        debian.org/security is wrong to say what it does maxwillb  <maxwillb@mailfence.com> - 2021-12-26 01:30 +0100
          Re: debian.org/security is wrong to say what it does "Andrew M.A. Cater" <amacater@einval.com> - 2021-12-26 13:30 +0100
            Re: debian.org/security is wrong to say what it does maxwillb  <maxwillb@mailfence.com> - 2021-12-26 21:40 +0100
              Re: debian.org/security is wrong to say what it does "Andrew M.A. Cater" <amacater@einval.com> - 2021-12-26 23:00 +0100
    Re: How to see the list of CRITICALLY vulnerable packages in Debian? Andy Smith <andy@strugglers.net> - 2021-12-25 16:10 +0100
      Re: How to see the list of CRITICALLY vulnerable packages in  Debian? maxwillb  <maxwillb@mailfence.com> - 2021-12-25 17:00 +0100
        Re: How to see the list of CRITICALLY vulnerable packages in Debian? <tomas@tuxteam.de> - 2021-12-25 17:20 +0100
          Re: How to see the list of CRITICALLY vulnerable packages in  Debian? maxwillb  <maxwillb@mailfence.com> - 2021-12-25 17:40 +0100
            Re: How to see the list of CRITICALLY vulnerable packages in Debian? <tomas@tuxteam.de> - 2021-12-25 17:50 +0100
              Re: How to see the list of CRITICALLY vulnerable packages in  Debian? maxwillb  <maxwillb@mailfence.com> - 2021-12-25 18:50 +0100

#243431 — How to see the list of CRITICALLY vulnerable packages in Debian?

Frommaxwillb <maxwillb@mailfence.com>
Date2021-12-25 00:20 +0100
SubjectHow to see the list of CRITICALLY vulnerable packages in Debian?
Message-ID<Dy20V-4Em-1@gated-at.bofh.it>
https://security-tracker.debian.org/tracker/status/release/stable

shows the list of packages currently considered vulnerable, but it does not show the severity.

For example, https://nvd.nist.gov/vuln/detail/CVE-2021-37973 has a CRITICAL severity but the Debian security tracker simply says "not assigned" (No dev so much as bothered to click on the 'NVD' link?)

Merry Christmas! 

-- 
Sent with https://mailfence.com  
Secure and private email

[toc] | [next] | [standalone]


#243437

FromDan Ritter <dsr@randomstring.org>
Date2021-12-25 13:50 +0100
Message-ID<DyeEN-3F6-1@gated-at.bofh.it>
In reply to#243431
maxwillb wrote: 
> https://security-tracker.debian.org/tracker/status/release/stable
> 
> shows the list of packages currently considered vulnerable, but it does not show the severity.

Severity is a matter of opinion. The first opinion should be
based on whether the package is even installed. Then on how
important the package is. Then, perhaps, what degree of
compromise is offered, and then how easy it is to exploit.  

But other people might have different ideas.

> For example, https://nvd.nist.gov/vuln/detail/CVE-2021-37973 has a CRITICAL severity but the Debian security tracker simply says "not assigned" (No dev so much as bothered to click on the 'NVD' link?)

Well, that one is easy: Debian doesn't ship Google Chrome. If
you have Chrome on your system, you got it from some other
organization.

There are five bugs noted for Chromium, though, in the
security-tracker.debian.org link that you already know.

You should start with the listings for linux, the kernel
package, since it's almost guaranteed you have that.

-dsr-

[toc] | [prev] | [next] | [standalone]


#243445 — Re: How to see the list of CRITICALLY vulnerable packages in Debian?

Frommaxwillb <maxwillb@mailfence.com>
Date2021-12-25 17:20 +0100
SubjectRe: How to see the list of CRITICALLY vulnerable packages in Debian?
Message-ID<DyhW1-5Ka-5@gated-at.bofh.it>
In reply to#243437

December 25, 2021 1:27:03 PM CET Dan Ritter <dsr@randomstring.org> wrote:maxwillb wrote: 

> Debian doesn't ship Google Chrome.

Chromium is a subset of Chrome. This vulnerability is in that subset. HTH

Merry Christmas!

-- 
Sent with https://mailfence.com  
Secure and private email

[toc] | [prev] | [next] | [standalone]


#243438

From"Andrew M.A. Cater" <amacater@einval.com>
Date2021-12-25 14:00 +0100
Message-ID<DyeOt-3Ig-3@gated-at.bofh.it>
In reply to#243431
On Sat, Dec 25, 2021 at 12:07:26AM +0100, maxwillb wrote:
> https://security-tracker.debian.org/tracker/status/release/stable
> 
> shows the list of packages currently considered vulnerable, but it does not show the severity.
> 
> For example, https://nvd.nist.gov/vuln/detail/CVE-2021-37973 has a CRITICAL severity but the Debian security tracker simply says "not assigned" (No dev so much as bothered to click on the 'NVD' link?)
> 
> Merry Christmas! 
> 
> -- 
> Sent with https://mailfence.com  
> Secure and private email
> 

Hi Maxwillb

If you click through any one of the CVE links, you find a link to a 
specific bug. That link also links to the bugs reported by other 
distributions, the Debian bug number and the NVD score - all the info
you may need.

The "not yet assigned" may be that the Debian Security Team haven't assigned it
a DSA number or decided on how severe it is "to Debian".

Taking the first one - first bug for aom - there's an assessment of which
releases are vulnerable. There's a fixed release in testing. 

It links to various other bugs in Chromium.

The next two CVEs for aom are also linked to the first bug and fixes
backported to stable by the maintainer. It's not as if people are massively
dropping the ball here, in spite of your apprehension.

Hope this helps,and with very best regards as ever.

Andy Cater

[toc] | [prev] | [next] | [standalone]


#243440 — Re: How to see the list of CRITICALLY vulnerable packages in Debian?

Frommaxwillb <maxwillb@mailfence.com>
Date2021-12-25 15:40 +0100
SubjectRe: How to see the list of CRITICALLY vulnerable packages in Debian?
Message-ID<Dygnf-4Im-1@gated-at.bofh.it>
In reply to#243438
December 25, 2021 1:51:39 PM CET "Andrew M.A. Cater" <amacater@einval.com> wrote:On Sat, Dec 25, 2021 at 12:07:26AM +0100, maxwillb wrote:

> It's not as if people are massively dropping the ball here, in spite of your apprehension.

I'm sure Debian is doing its best. It's just that it's not enough:

https://security-tracker.debian.org/tracker/CVE-2021-30521

~6 months old. HIGH severity on NVD. "Not yet assigned" on Debian.

https://security-tracker.debian.org/tracker/CVE-2021-37973

~3 months old. CRITICAL severity on NVD. "Not yet assigned" on Debian. 

etc. etc. ...


But I don't want to click on every one of these links. I just want to filter the vulnerabilities by their NVD severity. Hence this question.

-- 
Sent with https://mailfence.com  
Secure and private email

[toc] | [prev] | [next] | [standalone]


#243454 — Re: How to see the list of CRITICALLY vulnerable packages in Debian?

Frommaxwillb <maxwillb@mailfence.com>
Date2021-12-26 00:00 +0100
SubjectRe: How to see the list of CRITICALLY vulnerable packages in Debian?
Message-ID<Dyob7-13S-3@gated-at.bofh.it>
In reply to#243440
December 25, 2021 4:16:59 PM CET "Andrew M.A. Cater" <amacater@einval.com> wrote:On Sat, Dec 25, 2021 at 03:36:12PM +0100, maxwillb wrote:

> So you're raising issues that everyone knows but can't do a great deal about

Then what did you mean by "It's not as if people are massively dropping the ball here" ?

By the way, I'm not criticizing Debian. I know it's all volunteers, and Debian can't make them fix Chromium, or any other package on that list.

I just wanted to know if there was a way to filter this list by (NVD) severity.

Merry Christmas!

-- 
Sent with https://mailfence.com  
Secure and private email

[toc] | [prev] | [next] | [standalone]


#243457

From"Andrew M.A. Cater" <amacater@einval.com>
Date2021-12-26 13:10 +0100
Message-ID<DyAvD-iO-5@gated-at.bofh.it>
In reply to#243454
On Sat, Dec 25, 2021 at 11:51:50PM +0100, maxwillb wrote:
> December 25, 2021 4:16:59 PM CET "Andrew M.A. Cater" <amacater@einval.com> wrote:On Sat, Dec 25, 2021 at 03:36:12PM +0100, maxwillb wrote:
> 
> > So you're raising issues that everyone knows but can't do a great deal about
> 
> Then what did you mean by "It's not as if people are massively dropping the ball here" ?
> 

I meant that folk are aware: that we're not hiding information: that bug
information and NVD levels are available - though at the level of the
individual bug..

Debian does take part in co-ordinated responsible disclosure with other Linux
distributions, does maintain a security team - it's not as if the Project as
a whole doesn't care.

> By the way, I'm not criticizing Debian. I know it's all volunteers, and Debian can't make them fix Chromium, or any other package on that list.
> 
> I just wanted to know if there was a way to filter this list by (NVD) severity.

Check with the Debian security folk - ask on debian-security mailing list?
The best info I had was the URL I gave you at the beginning of one of my 
messages.

All the very best, as ever,

Andy Cater

[_Not_ one of the security folk]
> 
> Merry Christmas!
> 
> -- 
> Sent with https://mailfence.com  
> Secure and private email
> 

[toc] | [prev] | [next] | [standalone]


#243455 — debian.org/security is wrong to say what it does

Frommaxwillb <maxwillb@mailfence.com>
Date2021-12-26 01:30 +0100
Subjectdebian.org/security is wrong to say what it does
Message-ID<DypAd-22L-3@gated-at.bofh.it>
In reply to#243440
December 25, 2021 4:16:59 PM CET "Andrew M.A. Cater" <amacater@einval.com> wrote:

> So you're raising issues that everyone knows but can't do a great deal about given the difficulties

I hate to be a broken record, but you could edit https://www.debian.org/security/  so that it
does not say "We handle all security problems brought to our attention and ensure that they
are corrected within a reasonable timeframe. " and add a link to 
https://security-tracker.debian.org/tracker/status/release/stable instead.

Even though it does not allow you to filter vulnerabilities by severity, it is better than nothing.

Merry Christmas!

-- 
Sent with https://mailfence.com  
Secure and private email

[toc] | [prev] | [next] | [standalone]


#243458 — Re: debian.org/security is wrong to say what it does

From"Andrew M.A. Cater" <amacater@einval.com>
Date2021-12-26 13:30 +0100
SubjectRe: debian.org/security is wrong to say what it does
Message-ID<DyAOZ-pb-1@gated-at.bofh.it>
In reply to#243455
On Sun, Dec 26, 2021 at 01:19:53AM +0100, maxwillb wrote:
> December 25, 2021 4:16:59 PM CET "Andrew M.A. Cater" <amacater@einval.com> wrote:
> 
> > So you're raising issues that everyone knows but can't do a great deal about given the difficulties
> 
> I hate to be a broken record, but you could edit https://www.debian.org/security/  so that it
> does not say "We handle all security problems brought to our attention and ensure that they
> are corrected within a reasonable timeframe. " and add a link to 
> https://security-tracker.debian.org/tracker/status/release/stable instead.
> 
> Even though it does not allow you to filter vulnerabilities by severity, it is better than nothing.
> 
> Merry Christmas!
> 

Hi,

I hate to be a broken record but - the best information you have is
from the security bug tracker and, as it says, this is based on source
packages, not necessarily binaries built from that.

It's also explicitly noted as being
based from unstable - if fixes go in there, they are recorded and prior
releases are marked as vulnerable - fixes and backports happen -but
that doesn't mean that everything marked as vulnerable is still at 
risk.

It's also true to say that some people still run oldstable and would be
interested in vulnerabilities there for example.

[There's a reason I keep on about keeping yourself up to date / running the
latest stable release in this list: I (and others) also point out the 
experience that is needed if you want to run testing / unstable and the
relative level of security support.]

If you're unhappy with data presentation, feel free to contact the security
team

Andy Cater

> -- 
> Sent with https://mailfence.com  
> Secure and private email
> 

[toc] | [prev] | [next] | [standalone]


#243466 — Re: debian.org/security is wrong to say what it does

Frommaxwillb <maxwillb@mailfence.com>
Date2021-12-26 21:40 +0100
SubjectRe: debian.org/security is wrong to say what it does
Message-ID<DyItb-5at-1@gated-at.bofh.it>
In reply to#243458
December 26, 2021 1:25:30 PM CET "Andrew M.A. Cater" <amacater@einval.com> wrote:

> but that doesn't mean that everything marked as vulnerable is still at risk.

I couldn't understand what you meant, and figured you were referring to some extra hardening done by Debian. Did some googling, and apparently, it's the opposite. Debian disables Chromium's own hardening?

https://www.whonix.org/wiki/Dev/Chromium#Chromium_Debian_Package_Security

"""
Thus, the Debian Chromium has substantially worsened
security than an official version. However, despite this,
it may still be more secure than Firefox (Firefox never
had many of the disabled mitigations in the first place).
"""

> If you're unhappy with data presentation, feel free to contact the security team

Am I the only one unhappy with it? Are you happy with it?

-- 
Sent with https://mailfence.com  
Secure and private email

[toc] | [prev] | [next] | [standalone]


#243467 — Re: debian.org/security is wrong to say what it does

From"Andrew M.A. Cater" <amacater@einval.com>
Date2021-12-26 23:00 +0100
SubjectRe: debian.org/security is wrong to say what it does
Message-ID<DyJIB-5Rz-7@gated-at.bofh.it>
In reply to#243466
On Sun, Dec 26, 2021 at 09:36:47PM +0100, maxwillb wrote:
> December 26, 2021 1:25:30 PM CET "Andrew M.A. Cater" <amacater@einval.com> wrote:
> 
> > but that doesn't mean that everything marked as vulnerable is still at risk.
> 

Hi maxwillb

I've tried to explain what I understand by the security tracker.

The security tracker is based on sid / Debian unstable and if it is fixed
in Sid, it's marked as such and others are automatically marked as vulnerable.
That doesn't mean to say that each distribution point marked as vulnerable
remains vulnerable throughout the life of the distribution: maintainers
are constantly fixing stuff.

> I couldn't understand what you meant, and figured you were referring to some extra hardening done by Debian. Did some googling, and apparently, it's the opposite. Debian disables Chromium's own hardening?
> 
> https://www.whonix.org/wiki/Dev/Chromium#Chromium_Debian_Package_Security

Whonix is itself based on Debian. Each distribution does its own thing.

If you are not sure on what is patched or why, maintainers can 
probably tell you. Just reading patch sets very quickly there are 
bits that don't need to be included. If the only "official" build of
Chromium comes from Google/Alphabet, then it's not for Debian to set that,
for example, and Debian doesn't build for Android.

> 
> """
> Thus, the Debian Chromium has substantially worsened
> security than an official version. However, despite this,
> it may still be more secure than Firefox (Firefox never
> had many of the disabled mitigations in the first place).
> """
> 
> > If you're unhappy with data presentation, feel free to contact the security team
> 
> Am I the only one unhappy with it? Are you happy with it?
> 

I'm not particularly unhappy with it and not as upset as you appear to be.
I hang around here to try and help users: I publish the monthly FAQ
but I'm not necessarily authoritative and my opinions can always be very
wrong.

I think I've probably said enough on this topic: I'd hoped to be more clear
but it's obvious to me that it is probably not productive for me to labour
the point further. Happy to help where I can, however.

With every good wish, as ever,

Andy Cater

> -- 
> Sent with https://mailfence.com  
> Secure and private email
> 

[toc] | [prev] | [next] | [standalone]


#243441

FromAndy Smith <andy@strugglers.net>
Date2021-12-25 16:10 +0100
Message-ID<DygQh-58c-3@gated-at.bofh.it>
In reply to#243431
On Sat, Dec 25, 2021 at 12:07:26AM +0100, maxwillb wrote:
> No dev so much as bothered to click on the 'NVD' link?
> 
> Merry Christmas!

Dear max, I am the ghost of Christmas Open Source and I encourage
you to ask for a full refund from Debian and all other volunteer
projects that you are unsatisfied with!

WooooOOOooOh

[toc] | [prev] | [next] | [standalone]


#243443 — Re: How to see the list of CRITICALLY vulnerable packages in Debian?

Frommaxwillb <maxwillb@mailfence.com>
Date2021-12-25 17:00 +0100
SubjectRe: How to see the list of CRITICALLY vulnerable packages in Debian?
Message-ID<DyhCF-5nM-1@gated-at.bofh.it>
In reply to#243441

December 25, 2021 4:04:03 PM CET Andy Smith <andy@strugglers.net> wrote:On Sat, Dec 25, 2021 at 12:07:26AM +0100, maxwillb wrote:


> Dear max, I am the ghost of Christmas Open Source and I encourage you to ask for a full refund from Debian and all other volunteer projects that you are unsatisfied with!

I know that we are not allowed to criticize Debian, because it's free and made by volunteers. And I wasn't criticizing it. I was just correcting Andrew who claimed that Debian is "not dropping the ball".

Merry Christmas!

-- 
Sent with https://mailfence.com  
Secure and private email

[toc] | [prev] | [next] | [standalone]


#243444

From<tomas@tuxteam.de>
Date2021-12-25 17:20 +0100
Message-ID<DyhW1-5Ka-3@gated-at.bofh.it>
In reply to#243443

[Multipart message — attachments visible in raw view] — view raw

On Sat, Dec 25, 2021 at 04:56:31PM +0100, maxwillb wrote:
> 
> 
> December 25, 2021 4:04:03 PM CET Andy Smith <andy@strugglers.net> wrote:On Sat, Dec 25, 2021 at 12:07:26AM +0100, maxwillb wrote:
> 
> 
> > Dear max, I am the ghost of Christmas Open Source and I encourage you to ask for a full refund from Debian and all other volunteer projects that you are unsatisfied with!
> 
> I know that we are not allowed to criticize Debian [...]

?

I think you /are/ allowed to criticize whatever you want, but you have
to accept critique yourself in exchange.

And oh, if you want to correlate Debian's CVEs with some NVD database...
feel free to automate that. I'm sure people around Debian will support
that, as long as it is compatible with licenses and stuff.

> Merry Christmas!

Same to you all.

Cheers
-- 
t

[toc] | [prev] | [next] | [standalone]


#243448 — Re: How to see the list of CRITICALLY vulnerable packages in Debian?

Frommaxwillb <maxwillb@mailfence.com>
Date2021-12-25 17:40 +0100
SubjectRe: How to see the list of CRITICALLY vulnerable packages in Debian?
Message-ID<Dyifo-5Qr-9@gated-at.bofh.it>
In reply to#243444
December 25, 2021 5:11:20 PM CET tomas@tuxteam.de wrote:On Sat, Dec 25, 2021 at 04:56:31PM +0100, maxwillb wrote:

> some NVD database...

Do you know a better source that provides CVE impact metrics?

https://www.cvedetails.com/cve/CVE-2021-37973/

has this one too, but they list the outdated 6.8 rating, which NVD updated to 9.8 (because it's actively being exploited in the wild)

Merry Christmas!


-- 
Sent with https://mailfence.com  
Secure and private email

[toc] | [prev] | [next] | [standalone]


#243449

From<tomas@tuxteam.de>
Date2021-12-25 17:50 +0100
Message-ID<Dyip4-5TV-7@gated-at.bofh.it>
In reply to#243448

[Multipart message — attachments visible in raw view] — view raw

On Sat, Dec 25, 2021 at 05:32:58PM +0100, maxwillb wrote:
> December 25, 2021 5:11:20 PM CET tomas@tuxteam.de wrote:On Sat, Dec 25, 2021 at 04:56:31PM +0100, maxwillb wrote:
> 
> > some NVD database...
> 
> Do you know a better source that provides CVE impact metrics?

That's not the point, and you know :)

Different folks have different criteria for different reasons, so
whether *I* know a better (according to my criteria?) source is totally
irrelevant here.

Cheers
-- 
t

[toc] | [prev] | [next] | [standalone]


#243452 — Re: How to see the list of CRITICALLY vulnerable packages in Debian?

Frommaxwillb <maxwillb@mailfence.com>
Date2021-12-25 18:50 +0100
SubjectRe: How to see the list of CRITICALLY vulnerable packages in Debian?
Message-ID<Dyjl7-6sO-1@gated-at.bofh.it>
In reply to#243449
December 25, 2021 5:41:40 PM CET tomas@tuxteam.de wrote:On Sat, Dec 25, 2021 at 05:32:58PM +0100, maxwillb wrote:

> Different folks have different criteria for different reasons, so
> whether I know a better (according to my criteria?) source is totally
> irrelevant here.

There are no viable alternatives to NVD.

Merry Christmas!

-- 
Sent with https://mailfence.com  
Secure and private email

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.user


csiph-web