Bug 1448504 - Wrong criterion in OVAL files
Summary: Wrong criterion in OVAL files
Keywords:
Status: NEW
Alias: None
Product: Security Response
Classification: Other
Component: data
Version: unspecified
Hardware: Unspecified
OS: Unspecified
unspecified
low
Target Milestone: ---
Assignee: Nobody
QA Contact:
URL:
Whiteboard:
Depends On: 1444716
Blocks:
TreeView+ depends on / blocked
 
Reported: 2017-05-05 15:22 UTC by King's Way
Modified: 2023-07-07 08:34 UTC (History)
1 user (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description King's Way 2017-05-05 15:22:59 UTC
There is a mistake in the oval file provided here.(https://www.redhat.com/security/data/oval/Red_Hat_Enterprise_Linux_7.xml)

The definition of 'RHSA-2017:0372' does not provide a 'criterion' to check whether the kernel is compiled with target aarch64 or not.

Actually, the 'test criterion' (oval:com.redhat.rhsa:tst:20170372013) will always return true on RHEL7 of any other architecture.

So, it will make many tools fail at this...


--------------------------------------------------------------------------
wrong lines pasted below
--------------------------------------------------------------------------
<criteria operator="AND">
  <criteria operator="OR">
     <criterion comment="Red Hat Enterprise Linux 7 Client is installed" test_ref="oval:com.redhat.rhsa:tst:20140675001"/>
     <criterion comment="Red Hat Enterprise Linux 7 Server is installed" test_ref="oval:com.redhat.rhsa:tst:20140675002"/>
     <criterion comment="Red Hat Enterprise Linux 7 Workstation is installed" test_ref="oval:com.redhat.rhsa:tst:20140675003"/>
     <criterion comment="Red Hat Enterprise Linux 7 ComputeNode is installed" test_ref="oval:com.redhat.rhsa:tst:20140675004"/>
     </criteria>

     <criteria operator="OR">
       <criteria operator="AND">
         <criterion comment="kernel is earlier than 0:4.5.0-15.2.1.el7" test_ref="oval:com.redhat.rhsa:tst:20170372013"/>   
         <criterion comment="kernel is signed with Red Hat redhatrelease2 key"
......
......
--------------------------------------------------------------------------

Comment 2 Martin Preisler 2017-06-27 15:44:56 UTC
Thanks for reporting this bug. We are working towards fixing this and regenerating the OVAL feeds with the criterion added.


Note You need to log in before you can comment on or make changes to this bug.