/srv/irclogs.ubuntu.com/2021/11/22/#ubuntu-security.txt

=== BlackDex__ is now known as BlackDex
=== cpaelzer_ is now known as cpaelzer
=== ChanServ changed the topic of #ubuntu-security to: Twitter: @ubuntu_sec || https://usn.ubuntu.com || https://wiki.ubuntu.com/SecurityTeam || https://wiki.ubuntu.com/Security/Features || Community: amurray
tewardsec team, assuming you would know more about the answer(s) here: https://askubuntu.com/questions/1377027/security-oval-files-seem-to-give-false-positives18:40
tewardRE the OVAL files for sec vulns18:40
TJ-looks more like the USN just doesn't list the affected binaries correctly; the linked names are to source packages so there is a disjoint between binary and source18:46
teward*lets TJ or others write an answer*18:49
amurrayteward: source packages can produce multiple binary packages so when we publish USNs we hand-whittle down the list of binary packages which we mention in the USN to those which we believe to be actually affected (ie in this case since the vuln is in the mysql server we only mention this binary package in the USN, not the client libs)22:56
amurraybut for completeness, the OVAL contains all binary packages which come from the source package - since some customers are quite cautious about this sort of thing and so we then err on the side of caution for this22:58
amurrayas such the OVAL can give potential false positives but since the 'whittling down' which I mentioned above is best-effort, to be completely sure, it is better to install all update to all the binary packages from a given USN rather than mixing and matching (also this then helps avoid issues like having client libs of one version being incompatible with the server of another)22:59
amurrayoh I see sarnold just responded on the original askubuntu question - thanks :)23:01
sarnold:D23:01
sarnoldit's reassuring to see many of the same points in your answer, hehe23:01
amurrayyup - phew :)23:01
sarnoldit's funny, I started the answer iwth "Hello Phil, we try to trim.." and something in their system stripped off the greeting but didn't fix up my capitalization for me, so it looked like I posted "we try to trim...". Not a fan. It also kept my 'Thanks' at the end, which feels odd to strip a greeting but keep the parting..23:02
sarnoldat least the edit done quickly enough didn't mar the post with an "(edited)" thing for eternity. I'm not a fan of that :)23:03

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!