future-architect / vuls

Agent-less vulnerability scanner for Linux, FreeBSD, Container, WordPress, Programming language libraries, Network devices
https://vuls.io/
GNU General Public License v3.0
10.91k stars 1.16k forks source link

meltdown/spectre CVE vuls not detected !!! #581

Closed mareban closed 6 years ago

mareban commented 6 years ago

Hello,

We've tried to detect vulnerable linux systems (ex centos 7), but nothing reported !!! The CVE are in the DB but no vulnerabilities detected !!!

Do we miss something or kernel vulnerabilities are not detected ??

Thanks for your help.

CVE-2017-5753 '2018-01-05 20:20:31.629993705+01:002018-01-05 20:20:31.629993705+01:00CVE-2017-5753Z CVE-2017-5753Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.2018-01-04 08:29:00.257-05:002018-01-04 21:31:48.043-05:00 CVE-2017-5753Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.2018-01-04 08:29:00.257-05:002018-01-05 21:29:40.317-05:00 CVE-2017-5754 '2018-01-05 20:20:31.631828268+01:002018-01-05 20:20:31.631828268+01:00CVE-2017-5754Z CVE-2017-5754Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis of the data cache.2018-01-04 08:29:00.303-05:002018-01-04 21:31:48.153-05:00 CVE-2017-5754Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis of the data cache.

mareban commented 6 years ago

with -deep option it is OK :+1:

Thx