Some packages versions are enclosed between brackets
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
Ubuntu CVE Tracker |
Fix Released
|
Undecided
|
Unassigned |
Bug Description
By analyzing the oval data XML files, we realized that some packages versions are enclosed between brackets. This is happening only in the Trusty XML file.
Here is an example:
<linux-
<linux-def:evr datatype=
</linux-
And by parsing the XML file, we got this list of CVS with the same problem:
[0.10.25~
[0.15-2+
[0.15-2ubuntu1.1]
[0.15-2ubuntu1.2]
[0.15.1b-
[0.19.0-2ubuntu0.4]
[0.2.3.22-rc-1]
[0.2.4.
[0.2.4.
[0.3.6-1]
[0.3.6-
[0.3.6-
[0.5.5-
[0.6.0-1ubuntu0.1]
[0.6.2-3ubuntu2.1]
[0.8.0-
[1.0.0g-
[1.0.0g-
[1.0.2+
[1.06.27-1ubuntu7]
[1.0~+git0c502e
[1.10.6-1]
[1.12.1+
[1.16.0-1ubuntu1.1]
[1.16.33-
[1.17-5ubuntu0.1]
[1.2-1+
[1.2.12-
[1.2.2-2ubuntu1.1]
[1.2.4-1~ubuntu1.1]
[1.29-1ubuntu0.1]
[1.3-1.1ubuntu1.1]
[1.3.1-1ubuntu5.1]
[1.3.18-1ubuntu3.1]
[1.3.6p1-
[1.4.22-
[1.4.22-
[1.4.3-2ubuntu0.1]
[1.4.3-2ubuntu0.2]
[1.4.6-2ubuntu0.1]
[1.4.7-1]
[1.4.7-1ubuntu0.1]
[1.5.2-1]
[1.5.4+dfsg-1]
[1.8.11-5ubuntu7.1]
[1.9.17.
[1.9.3-2ubuntu0.1]
[14.4.1-3ubuntu1.1]
[1:1.5.
[1:16.b.
[1:2.10.
[1:2.10.
[1:2.10.
[1:2.10.
[1:5.6-2ubuntu0.1]
[2.0.5-
[2.0b4-
[2.3.4-
[2.3.4-
[2.3.6-
[2.3.6-
[2.36.0-0ubuntu3.1]
[2.4.16+
[2.4.8+
[2.5.2.
[2.6.3-
[2.6.4-
[2.6.5-
[2.6.6-
[2.6.6-6]
[2.7-5+
[2.8.2-1ubuntu1.3]
[2.8.2-1ubuntu1.4]
[20161222-
[2:1.14.4-1ubuntu2]
[2:1.15.
[2:1.15.
[2:1.15.
[2:1.15.
[2:2.8.
[3.0.21-
[3.0.5-2ubuntu0.1]
[3.0b2-1ubuntu0.1]
[3.1-10.
[3.1.1-
[3.1.1-
[3.1.2-1ubuntu0.1]
[3.15.4-3ubuntu0.1]
[3.2.8+
[3.4.3-1ubuntu1.2]
[3.4.3-1ubuntu1.3]
[4.0.4+
[4.01.0-3ubuntu3.1]
[4.3.3-1ubuntu0.1]
[4:4.0.
[4:4.13.
[4:4.13.
[4:4.13.
[4:4.13.
[4:4.13.
[4:4.8.
[4:4.8.
[5.1.5-5ubuntu0.1]
[5.6.1-
[5.6.1-
[5.9.1-1ubuntu1.1]
[6.0.39-1ubuntu0.1]
[6.1.26-1ubuntu1.2]
[6.5.0+
[8.14.4-
[9.20.1~
[9.20.1~
[9.20.1~
Hi guys, do you have any update related to this report?
The thing is that we have some automatic mechanisms to analyze the vulnerability reports and compare versions with the versions of the packages installed in the system. So, this is causing some issues.
We would like to know whether this will be kept in this way or not so we may decide if we have to implement a workaround on our side.
Thanks, I'll really appreciate your comments.