I want to check the list of CVEs fixed or not in CentOS 8. I tried this command "rpm -qip --changelog *.rpm | grep CVE_XXXX_XXXX". This is not helping me. For example, if CVE_XXXX_XXXX fixed in CentOS 7.7, then its showing in CentOS 8.
The requirement is If I search for CVE-X in CentOS8, then it should show whether CVE is fixed in current release or in previous releases.
Is there any command for this?
Please provide your inputs.
Thank you.
How to check whether list of CVEs are fixed or not?
-
- Posts: 1
- Joined: 2019/10/28 08:09:21
Re: How to check whether list of CVEs are fixed or not?
The command you want is rpm -q --changelog $packagename for each package you want to look at the changelog for. This will require the package to be installed. If you have the packages downloaded and not installed then you need to amend the command to use -qp and add the full filename to the command instead of just the package name.
No. Using rpm -q --changelog just tells you if it's fixed. It doesn't tell you about when it was fixed, for that you need to look at the changelog in more detail and extract the date lines from it as well. The important thing is "is it fixed" not when.The requirement is If I search for CVE-X in CentOS8, then it should show whether CVE is fixed in current release or in previous releases.
The future appears to be RHEL or Debian. I think I'm going Debian.
Info for USB installs on http://wiki.centos.org/HowTos/InstallFromUSBkey
CentOS 5 and 6 are deadest, do not use them.
Use the FAQ Luke
Info for USB installs on http://wiki.centos.org/HowTos/InstallFromUSBkey
CentOS 5 and 6 are deadest, do not use them.
Use the FAQ Luke