Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 912369 - CPE for app-crypto/mit-krb5 is incorrect and will lead to CVE's getting filed inaccurately
Summary: CPE for app-crypto/mit-krb5 is incorrect and will lead to CVE's getting filed...
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Misc (show other bugs)
Hardware: All Linux
: Normal minor
Assignee: Gentoo Security
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2023-08-16 20:05 UTC by Michael Kochera
Modified: 2023-08-17 06:23 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Michael Kochera 2023-08-16 20:05:44 UTC
The CPE currently is cpe:/a:mit:kerberos and needs to be updated to cpe:/a:mit:kerberos_5. It seems to me the transition from cpe 2.2 to cpe 2.3 cause a change for this cpe. It used to have the 5 which is part of the package name as part of the version string in the cpe when it was in 2.2. This seems to have changed in 2.3 which is an improvement as the 5 shouldn't be a part of the version string anyways.
Comment 1 Larry the Git Cow gentoo-dev 2023-08-17 06:22:54 UTC
The bug has been closed via the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=89ae9a135fc72a539ae9e5603dff2524b78e8870

commit 89ae9a135fc72a539ae9e5603dff2524b78e8870
Author:     Michael Kochera <kochera@google.com>
AuthorDate: 2023-08-11 03:24:23 +0000
Commit:     Sam James <sam@gentoo.org>
CommitDate: 2023-08-17 06:22:35 +0000

    app-crypt/mit-krb5: Fix cpe_uri
    
    Closes: https://bugs.gentoo.org/912369
    Closes: https://github.com/gentoo/gentoo/pull/32251
    Signed-off-by: Michael Kochera <kochera@google.com>
    Signed-off-by: Sam James <sam@gentoo.org>

 app-crypt/mit-krb5/metadata.xml | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)
Comment 2 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2023-08-17 06:23:24 UTC
Thanks!