canonical / sec-cvescan

Analyzes an Ubuntu system and checks for unpatched vulnerabilities.
GNU General Public License v3.0
87 stars 31 forks source link

CVE-2019-3466 outstanding when postgresql-all = 10+190ubuntu0.1 #79

Open stevegnz opened 3 years ago

stevegnz commented 3 years ago

cvescan reports an issue with CVE-2019-3466 when the packages are at "10+" but the changelog for those packages indicate they are patched.

✅ Ubuntu vulnerability database successfully downloaded! ✅ Scan complete!

CVE ID PRIORITY PACKAGE FIXED VERSION REPOSITORY CVE-2019-3466 medium postgresql-all 190ubuntu0.1 Ubuntu Archive

Summary


Ubuntu Release bionic Installed Packages 969 CVE Priority All Unique Packages Fixable by Patching 1 Unique CVEs Fixable by Patching 1 Vulnerabilities Fixable by Patching 1 Fixes Available by apt-get upgrade 1


Desired=Unknown/Install/Remove/Purge/Hold | Status=Not/Inst/Conf-files/Unpacked/halF-conf/Half-inst/trig-aWait/Trig-pend |/ Err?=(none)/Reinst-required (Status,Err: uppercase=bad) ||/ Name Version Architecture Description +++-================================================-=============================-=============================-===================================================================================================== ii postgresql-all 10+190ubuntu0.1 all metapackage depending on all PostgreSQL server packages

Get:1 https://changelogs.ubuntu.com postgresql-common 190ubuntu0.1 Changelog [188 kB] postgresql-common (190ubuntu0.1) bionic-security; urgency=medium