sys-libs/ldb is part of the samba project so the CPE string in: https://gitweb.gentoo.org/repo/gentoo.git/tree/sys-libs/ldb/metadata.xml is cpe:/a:samba:samba A consequence of this is CVE matching tooling attribues the ldb version to samba rather than to ldb. Since these versions do not correspond it makes sense to drop the CPE string for ldb for now since we have coverage for `cpe:/a:samba:samba` in the samba package. Reproducible: Always
The bug has been closed via the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=66838e3f9b6f2748ec6000df60ca91244bad9e51 commit 66838e3f9b6f2748ec6000df60ca91244bad9e51 Author: Ben Reich <benreich@chromium.org> AuthorDate: 2023-09-20 02:52:32 +0000 Commit: Mike Frysinger <vapier@gentoo.org> CommitDate: 2023-12-05 16:42:52 +0000 sys-libs/ldb: Remove samba CPE from metadata.xml Closes: https://bugs.gentoo.org/902905 Signed-off-by: Ben Reich <benreich@chromium.org> Signed-off-by: Mike Frysinger <vapier@chromium.org> Signed-off-by: Mike Frysinger <vapier@gentoo.org> sys-libs/ldb/metadata.xml | 3 --- 1 file changed, 3 deletions(-)