future-architect/vuls












Do you want to work on this issue?
You can request for a bounty in order to promote it!
False Positives in Redhat 8.6 EUS #1989
wagde-orca posted onGitHub
What did you do? (required. The issue will be closed when not provided.)
I ran vuls on redhat 8.6 with curl 7.61.1-22.el8_6.4 installed
What did you expect to happen?
I expected to get 0:7.61.1-22.el8_6.12 as the fixed version
What happened instead?
I got 0:7.61.1-30.el8 as the fixed version
Redhat has a separate oval file for redhat 8.6 EUS rhel-8.6-eus.oval.xml.bz2
and currently goval-dictionary and vuls does not fetch it and fetch only the redhat 8 oval file and this is causing the FP... as you can see in the redhat security tracker (https://access.redhat.com/security/cve/CVE-2022-35252) they mention 8.6 EUS separately and I guess vuls should behave according to this