Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #243431 > unrolled thread
| Started by | maxwillb <maxwillb@mailfence.com> |
|---|---|
| First post | 2021-12-25 00:20 +0100 |
| Last post | 2021-12-25 18:50 +0100 |
| Articles | 17 — 5 participants |
Back to article view | Back to linux.debian.user
How to see the list of CRITICALLY vulnerable packages in Debian? maxwillb <maxwillb@mailfence.com> - 2021-12-25 00:20 +0100
Re: How to see the list of CRITICALLY vulnerable packages in Debian? Dan Ritter <dsr@randomstring.org> - 2021-12-25 13:50 +0100
Re: How to see the list of CRITICALLY vulnerable packages in Debian? maxwillb <maxwillb@mailfence.com> - 2021-12-25 17:20 +0100
Re: How to see the list of CRITICALLY vulnerable packages in Debian? "Andrew M.A. Cater" <amacater@einval.com> - 2021-12-25 14:00 +0100
Re: How to see the list of CRITICALLY vulnerable packages in Debian? maxwillb <maxwillb@mailfence.com> - 2021-12-25 15:40 +0100
Re: How to see the list of CRITICALLY vulnerable packages in Debian? maxwillb <maxwillb@mailfence.com> - 2021-12-26 00:00 +0100
Re: How to see the list of CRITICALLY vulnerable packages in Debian? "Andrew M.A. Cater" <amacater@einval.com> - 2021-12-26 13:10 +0100
debian.org/security is wrong to say what it does maxwillb <maxwillb@mailfence.com> - 2021-12-26 01:30 +0100
Re: debian.org/security is wrong to say what it does "Andrew M.A. Cater" <amacater@einval.com> - 2021-12-26 13:30 +0100
Re: debian.org/security is wrong to say what it does maxwillb <maxwillb@mailfence.com> - 2021-12-26 21:40 +0100
Re: debian.org/security is wrong to say what it does "Andrew M.A. Cater" <amacater@einval.com> - 2021-12-26 23:00 +0100
Re: How to see the list of CRITICALLY vulnerable packages in Debian? Andy Smith <andy@strugglers.net> - 2021-12-25 16:10 +0100
Re: How to see the list of CRITICALLY vulnerable packages in Debian? maxwillb <maxwillb@mailfence.com> - 2021-12-25 17:00 +0100
Re: How to see the list of CRITICALLY vulnerable packages in Debian? <tomas@tuxteam.de> - 2021-12-25 17:20 +0100
Re: How to see the list of CRITICALLY vulnerable packages in Debian? maxwillb <maxwillb@mailfence.com> - 2021-12-25 17:40 +0100
Re: How to see the list of CRITICALLY vulnerable packages in Debian? <tomas@tuxteam.de> - 2021-12-25 17:50 +0100
Re: How to see the list of CRITICALLY vulnerable packages in Debian? maxwillb <maxwillb@mailfence.com> - 2021-12-25 18:50 +0100
| From | maxwillb <maxwillb@mailfence.com> |
|---|---|
| Date | 2021-12-25 00:20 +0100 |
| Subject | How to see the list of CRITICALLY vulnerable packages in Debian? |
| Message-ID | <Dy20V-4Em-1@gated-at.bofh.it> |
https://security-tracker.debian.org/tracker/status/release/stable shows the list of packages currently considered vulnerable, but it does not show the severity. For example, https://nvd.nist.gov/vuln/detail/CVE-2021-37973 has a CRITICAL severity but the Debian security tracker simply says "not assigned" (No dev so much as bothered to click on the 'NVD' link?) Merry Christmas! -- Sent with https://mailfence.com Secure and private email
[toc] | [next] | [standalone]
| From | Dan Ritter <dsr@randomstring.org> |
|---|---|
| Date | 2021-12-25 13:50 +0100 |
| Message-ID | <DyeEN-3F6-1@gated-at.bofh.it> |
| In reply to | #243431 |
maxwillb wrote: > https://security-tracker.debian.org/tracker/status/release/stable > > shows the list of packages currently considered vulnerable, but it does not show the severity. Severity is a matter of opinion. The first opinion should be based on whether the package is even installed. Then on how important the package is. Then, perhaps, what degree of compromise is offered, and then how easy it is to exploit. But other people might have different ideas. > For example, https://nvd.nist.gov/vuln/detail/CVE-2021-37973 has a CRITICAL severity but the Debian security tracker simply says "not assigned" (No dev so much as bothered to click on the 'NVD' link?) Well, that one is easy: Debian doesn't ship Google Chrome. If you have Chrome on your system, you got it from some other organization. There are five bugs noted for Chromium, though, in the security-tracker.debian.org link that you already know. You should start with the listings for linux, the kernel package, since it's almost guaranteed you have that. -dsr-
[toc] | [prev] | [next] | [standalone]
| From | maxwillb <maxwillb@mailfence.com> |
|---|---|
| Date | 2021-12-25 17:20 +0100 |
| Subject | Re: How to see the list of CRITICALLY vulnerable packages in Debian? |
| Message-ID | <DyhW1-5Ka-5@gated-at.bofh.it> |
| In reply to | #243437 |
December 25, 2021 1:27:03 PM CET Dan Ritter <dsr@randomstring.org> wrote:maxwillb wrote: > Debian doesn't ship Google Chrome. Chromium is a subset of Chrome. This vulnerability is in that subset. HTH Merry Christmas! -- Sent with https://mailfence.com Secure and private email
[toc] | [prev] | [next] | [standalone]
| From | "Andrew M.A. Cater" <amacater@einval.com> |
|---|---|
| Date | 2021-12-25 14:00 +0100 |
| Message-ID | <DyeOt-3Ig-3@gated-at.bofh.it> |
| In reply to | #243431 |
On Sat, Dec 25, 2021 at 12:07:26AM +0100, maxwillb wrote: > https://security-tracker.debian.org/tracker/status/release/stable > > shows the list of packages currently considered vulnerable, but it does not show the severity. > > For example, https://nvd.nist.gov/vuln/detail/CVE-2021-37973 has a CRITICAL severity but the Debian security tracker simply says "not assigned" (No dev so much as bothered to click on the 'NVD' link?) > > Merry Christmas! > > -- > Sent with https://mailfence.com > Secure and private email > Hi Maxwillb If you click through any one of the CVE links, you find a link to a specific bug. That link also links to the bugs reported by other distributions, the Debian bug number and the NVD score - all the info you may need. The "not yet assigned" may be that the Debian Security Team haven't assigned it a DSA number or decided on how severe it is "to Debian". Taking the first one - first bug for aom - there's an assessment of which releases are vulnerable. There's a fixed release in testing. It links to various other bugs in Chromium. The next two CVEs for aom are also linked to the first bug and fixes backported to stable by the maintainer. It's not as if people are massively dropping the ball here, in spite of your apprehension. Hope this helps,and with very best regards as ever. Andy Cater
[toc] | [prev] | [next] | [standalone]
| From | maxwillb <maxwillb@mailfence.com> |
|---|---|
| Date | 2021-12-25 15:40 +0100 |
| Subject | Re: How to see the list of CRITICALLY vulnerable packages in Debian? |
| Message-ID | <Dygnf-4Im-1@gated-at.bofh.it> |
| In reply to | #243438 |
December 25, 2021 1:51:39 PM CET "Andrew M.A. Cater" <amacater@einval.com> wrote:On Sat, Dec 25, 2021 at 12:07:26AM +0100, maxwillb wrote: > It's not as if people are massively dropping the ball here, in spite of your apprehension. I'm sure Debian is doing its best. It's just that it's not enough: https://security-tracker.debian.org/tracker/CVE-2021-30521 ~6 months old. HIGH severity on NVD. "Not yet assigned" on Debian. https://security-tracker.debian.org/tracker/CVE-2021-37973 ~3 months old. CRITICAL severity on NVD. "Not yet assigned" on Debian. etc. etc. ... But I don't want to click on every one of these links. I just want to filter the vulnerabilities by their NVD severity. Hence this question. -- Sent with https://mailfence.com Secure and private email
[toc] | [prev] | [next] | [standalone]
| From | maxwillb <maxwillb@mailfence.com> |
|---|---|
| Date | 2021-12-26 00:00 +0100 |
| Subject | Re: How to see the list of CRITICALLY vulnerable packages in Debian? |
| Message-ID | <Dyob7-13S-3@gated-at.bofh.it> |
| In reply to | #243440 |
December 25, 2021 4:16:59 PM CET "Andrew M.A. Cater" <amacater@einval.com> wrote:On Sat, Dec 25, 2021 at 03:36:12PM +0100, maxwillb wrote: > So you're raising issues that everyone knows but can't do a great deal about Then what did you mean by "It's not as if people are massively dropping the ball here" ? By the way, I'm not criticizing Debian. I know it's all volunteers, and Debian can't make them fix Chromium, or any other package on that list. I just wanted to know if there was a way to filter this list by (NVD) severity. Merry Christmas! -- Sent with https://mailfence.com Secure and private email
[toc] | [prev] | [next] | [standalone]
| From | "Andrew M.A. Cater" <amacater@einval.com> |
|---|---|
| Date | 2021-12-26 13:10 +0100 |
| Message-ID | <DyAvD-iO-5@gated-at.bofh.it> |
| In reply to | #243454 |
On Sat, Dec 25, 2021 at 11:51:50PM +0100, maxwillb wrote: > December 25, 2021 4:16:59 PM CET "Andrew M.A. Cater" <amacater@einval.com> wrote:On Sat, Dec 25, 2021 at 03:36:12PM +0100, maxwillb wrote: > > > So you're raising issues that everyone knows but can't do a great deal about > > Then what did you mean by "It's not as if people are massively dropping the ball here" ? > I meant that folk are aware: that we're not hiding information: that bug information and NVD levels are available - though at the level of the individual bug.. Debian does take part in co-ordinated responsible disclosure with other Linux distributions, does maintain a security team - it's not as if the Project as a whole doesn't care. > By the way, I'm not criticizing Debian. I know it's all volunteers, and Debian can't make them fix Chromium, or any other package on that list. > > I just wanted to know if there was a way to filter this list by (NVD) severity. Check with the Debian security folk - ask on debian-security mailing list? The best info I had was the URL I gave you at the beginning of one of my messages. All the very best, as ever, Andy Cater [_Not_ one of the security folk] > > Merry Christmas! > > -- > Sent with https://mailfence.com > Secure and private email >
[toc] | [prev] | [next] | [standalone]
| From | maxwillb <maxwillb@mailfence.com> |
|---|---|
| Date | 2021-12-26 01:30 +0100 |
| Subject | debian.org/security is wrong to say what it does |
| Message-ID | <DypAd-22L-3@gated-at.bofh.it> |
| In reply to | #243440 |
December 25, 2021 4:16:59 PM CET "Andrew M.A. Cater" <amacater@einval.com> wrote: > So you're raising issues that everyone knows but can't do a great deal about given the difficulties I hate to be a broken record, but you could edit https://www.debian.org/security/ so that it does not say "We handle all security problems brought to our attention and ensure that they are corrected within a reasonable timeframe. " and add a link to https://security-tracker.debian.org/tracker/status/release/stable instead. Even though it does not allow you to filter vulnerabilities by severity, it is better than nothing. Merry Christmas! -- Sent with https://mailfence.com Secure and private email
[toc] | [prev] | [next] | [standalone]
| From | "Andrew M.A. Cater" <amacater@einval.com> |
|---|---|
| Date | 2021-12-26 13:30 +0100 |
| Subject | Re: debian.org/security is wrong to say what it does |
| Message-ID | <DyAOZ-pb-1@gated-at.bofh.it> |
| In reply to | #243455 |
On Sun, Dec 26, 2021 at 01:19:53AM +0100, maxwillb wrote: > December 25, 2021 4:16:59 PM CET "Andrew M.A. Cater" <amacater@einval.com> wrote: > > > So you're raising issues that everyone knows but can't do a great deal about given the difficulties > > I hate to be a broken record, but you could edit https://www.debian.org/security/ so that it > does not say "We handle all security problems brought to our attention and ensure that they > are corrected within a reasonable timeframe. " and add a link to > https://security-tracker.debian.org/tracker/status/release/stable instead. > > Even though it does not allow you to filter vulnerabilities by severity, it is better than nothing. > > Merry Christmas! > Hi, I hate to be a broken record but - the best information you have is from the security bug tracker and, as it says, this is based on source packages, not necessarily binaries built from that. It's also explicitly noted as being based from unstable - if fixes go in there, they are recorded and prior releases are marked as vulnerable - fixes and backports happen -but that doesn't mean that everything marked as vulnerable is still at risk. It's also true to say that some people still run oldstable and would be interested in vulnerabilities there for example. [There's a reason I keep on about keeping yourself up to date / running the latest stable release in this list: I (and others) also point out the experience that is needed if you want to run testing / unstable and the relative level of security support.] If you're unhappy with data presentation, feel free to contact the security team Andy Cater > -- > Sent with https://mailfence.com > Secure and private email >
[toc] | [prev] | [next] | [standalone]
| From | maxwillb <maxwillb@mailfence.com> |
|---|---|
| Date | 2021-12-26 21:40 +0100 |
| Subject | Re: debian.org/security is wrong to say what it does |
| Message-ID | <DyItb-5at-1@gated-at.bofh.it> |
| In reply to | #243458 |
December 26, 2021 1:25:30 PM CET "Andrew M.A. Cater" <amacater@einval.com> wrote: > but that doesn't mean that everything marked as vulnerable is still at risk. I couldn't understand what you meant, and figured you were referring to some extra hardening done by Debian. Did some googling, and apparently, it's the opposite. Debian disables Chromium's own hardening? https://www.whonix.org/wiki/Dev/Chromium#Chromium_Debian_Package_Security """ Thus, the Debian Chromium has substantially worsened security than an official version. However, despite this, it may still be more secure than Firefox (Firefox never had many of the disabled mitigations in the first place). """ > If you're unhappy with data presentation, feel free to contact the security team Am I the only one unhappy with it? Are you happy with it? -- Sent with https://mailfence.com Secure and private email
[toc] | [prev] | [next] | [standalone]
| From | "Andrew M.A. Cater" <amacater@einval.com> |
|---|---|
| Date | 2021-12-26 23:00 +0100 |
| Subject | Re: debian.org/security is wrong to say what it does |
| Message-ID | <DyJIB-5Rz-7@gated-at.bofh.it> |
| In reply to | #243466 |
On Sun, Dec 26, 2021 at 09:36:47PM +0100, maxwillb wrote: > December 26, 2021 1:25:30 PM CET "Andrew M.A. Cater" <amacater@einval.com> wrote: > > > but that doesn't mean that everything marked as vulnerable is still at risk. > Hi maxwillb I've tried to explain what I understand by the security tracker. The security tracker is based on sid / Debian unstable and if it is fixed in Sid, it's marked as such and others are automatically marked as vulnerable. That doesn't mean to say that each distribution point marked as vulnerable remains vulnerable throughout the life of the distribution: maintainers are constantly fixing stuff. > I couldn't understand what you meant, and figured you were referring to some extra hardening done by Debian. Did some googling, and apparently, it's the opposite. Debian disables Chromium's own hardening? > > https://www.whonix.org/wiki/Dev/Chromium#Chromium_Debian_Package_Security Whonix is itself based on Debian. Each distribution does its own thing. If you are not sure on what is patched or why, maintainers can probably tell you. Just reading patch sets very quickly there are bits that don't need to be included. If the only "official" build of Chromium comes from Google/Alphabet, then it's not for Debian to set that, for example, and Debian doesn't build for Android. > > """ > Thus, the Debian Chromium has substantially worsened > security than an official version. However, despite this, > it may still be more secure than Firefox (Firefox never > had many of the disabled mitigations in the first place). > """ > > > If you're unhappy with data presentation, feel free to contact the security team > > Am I the only one unhappy with it? Are you happy with it? > I'm not particularly unhappy with it and not as upset as you appear to be. I hang around here to try and help users: I publish the monthly FAQ but I'm not necessarily authoritative and my opinions can always be very wrong. I think I've probably said enough on this topic: I'd hoped to be more clear but it's obvious to me that it is probably not productive for me to labour the point further. Happy to help where I can, however. With every good wish, as ever, Andy Cater > -- > Sent with https://mailfence.com > Secure and private email >
[toc] | [prev] | [next] | [standalone]
| From | Andy Smith <andy@strugglers.net> |
|---|---|
| Date | 2021-12-25 16:10 +0100 |
| Message-ID | <DygQh-58c-3@gated-at.bofh.it> |
| In reply to | #243431 |
On Sat, Dec 25, 2021 at 12:07:26AM +0100, maxwillb wrote: > No dev so much as bothered to click on the 'NVD' link? > > Merry Christmas! Dear max, I am the ghost of Christmas Open Source and I encourage you to ask for a full refund from Debian and all other volunteer projects that you are unsatisfied with! WooooOOOooOh
[toc] | [prev] | [next] | [standalone]
| From | maxwillb <maxwillb@mailfence.com> |
|---|---|
| Date | 2021-12-25 17:00 +0100 |
| Subject | Re: How to see the list of CRITICALLY vulnerable packages in Debian? |
| Message-ID | <DyhCF-5nM-1@gated-at.bofh.it> |
| In reply to | #243441 |
December 25, 2021 4:04:03 PM CET Andy Smith <andy@strugglers.net> wrote:On Sat, Dec 25, 2021 at 12:07:26AM +0100, maxwillb wrote: > Dear max, I am the ghost of Christmas Open Source and I encourage you to ask for a full refund from Debian and all other volunteer projects that you are unsatisfied with! I know that we are not allowed to criticize Debian, because it's free and made by volunteers. And I wasn't criticizing it. I was just correcting Andrew who claimed that Debian is "not dropping the ball". Merry Christmas! -- Sent with https://mailfence.com Secure and private email
[toc] | [prev] | [next] | [standalone]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2021-12-25 17:20 +0100 |
| Message-ID | <DyhW1-5Ka-3@gated-at.bofh.it> |
| In reply to | #243443 |
[Multipart message — attachments visible in raw view] — view raw
On Sat, Dec 25, 2021 at 04:56:31PM +0100, maxwillb wrote: > > > December 25, 2021 4:04:03 PM CET Andy Smith <andy@strugglers.net> wrote:On Sat, Dec 25, 2021 at 12:07:26AM +0100, maxwillb wrote: > > > > Dear max, I am the ghost of Christmas Open Source and I encourage you to ask for a full refund from Debian and all other volunteer projects that you are unsatisfied with! > > I know that we are not allowed to criticize Debian [...] ? I think you /are/ allowed to criticize whatever you want, but you have to accept critique yourself in exchange. And oh, if you want to correlate Debian's CVEs with some NVD database... feel free to automate that. I'm sure people around Debian will support that, as long as it is compatible with licenses and stuff. > Merry Christmas! Same to you all. Cheers -- t
[toc] | [prev] | [next] | [standalone]
| From | maxwillb <maxwillb@mailfence.com> |
|---|---|
| Date | 2021-12-25 17:40 +0100 |
| Subject | Re: How to see the list of CRITICALLY vulnerable packages in Debian? |
| Message-ID | <Dyifo-5Qr-9@gated-at.bofh.it> |
| In reply to | #243444 |
December 25, 2021 5:11:20 PM CET tomas@tuxteam.de wrote:On Sat, Dec 25, 2021 at 04:56:31PM +0100, maxwillb wrote: > some NVD database... Do you know a better source that provides CVE impact metrics? https://www.cvedetails.com/cve/CVE-2021-37973/ has this one too, but they list the outdated 6.8 rating, which NVD updated to 9.8 (because it's actively being exploited in the wild) Merry Christmas! -- Sent with https://mailfence.com Secure and private email
[toc] | [prev] | [next] | [standalone]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2021-12-25 17:50 +0100 |
| Message-ID | <Dyip4-5TV-7@gated-at.bofh.it> |
| In reply to | #243448 |
[Multipart message — attachments visible in raw view] — view raw
On Sat, Dec 25, 2021 at 05:32:58PM +0100, maxwillb wrote: > December 25, 2021 5:11:20 PM CET tomas@tuxteam.de wrote:On Sat, Dec 25, 2021 at 04:56:31PM +0100, maxwillb wrote: > > > some NVD database... > > Do you know a better source that provides CVE impact metrics? That's not the point, and you know :) Different folks have different criteria for different reasons, so whether *I* know a better (according to my criteria?) source is totally irrelevant here. Cheers -- t
[toc] | [prev] | [next] | [standalone]
| From | maxwillb <maxwillb@mailfence.com> |
|---|---|
| Date | 2021-12-25 18:50 +0100 |
| Subject | Re: How to see the list of CRITICALLY vulnerable packages in Debian? |
| Message-ID | <Dyjl7-6sO-1@gated-at.bofh.it> |
| In reply to | #243449 |
December 25, 2021 5:41:40 PM CET tomas@tuxteam.de wrote:On Sat, Dec 25, 2021 at 05:32:58PM +0100, maxwillb wrote: > Different folks have different criteria for different reasons, so > whether I know a better (according to my criteria?) source is totally > irrelevant here. There are no viable alternatives to NVD. Merry Christmas! -- Sent with https://mailfence.com Secure and private email
[toc] | [prev] | [standalone]
Back to top | Article view | linux.debian.user
csiph-web