CESNET / pakiti-server

Pakiti provides a monitoring mechanism to check the patching status of Linux systems.
BSD 2-Clause "Simplified" License
49 stars 35 forks source link

Version comparison problem for release candidates #167

Closed sbraz closed 4 years ago

sbraz commented 4 years ago

Hi, I think that there is a problem with the way release candidates are handled. For instance, CVE-2018-14647 applies to packages older than 2.7.15~rc1-1ubuntu0. I have 2.7.15-4ubuntu4~18.04.2 installed but pakiti still reports it as vulnerable.

kouril commented 4 years ago

I've updated the method to compare debian-based packages, I believe that should also fix your problem. Feel free to re-open the ticket if you see the problem still occuring.