oscap with com.ubuntu.xenial.cve.oval.xml wrongly reports many unpatched (and unknown) non-installed packages on Ubuntu Xenial 16.04.1 LTS
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
Ubuntu CVE Tracker |
Fix Released
|
Undecided
|
Unassigned | ||
openscap (Ubuntu) |
Invalid
|
Undecided
|
Unassigned |
Bug Description
Steps to reproduce:
1. Download OVAL definitions
cd /tmp
wget https:/
2. Install OpenSCAP
2a. from official repository
sudo apt-get install libopenscap8
2b. build from sources
(see my comment 27 on https:/
3. Check system and open report
oscap oval eval --results /tmp/results-
firefox /tmp/report-
Expected results:
Fully upgraded system should have
0 Non-Compliant/
0 Unknown
OVAL scanning results.
Actual results:
Fully upgraded system has
1531 Non-Compliant/
1690 Unknown
OVAL scanning results.
Notes:
1. 'oscap oval eval' command works normally on Ubuntu 12.04 LTS and 14.04 LTS with openscap from https:/
2. Error about "com.ubuntu.
ProblemType: Bug
DistroRelease: Ubuntu 16.04
Package: libopenscap8 1.2.8-1
ProcVersionSign
Uname: Linux 4.4.0-59-generic i686
ApportVersion: 2.20.1-0ubuntu2.5
Architecture: i386
CurrentDesktop: MATE
Date: Mon Jan 23 20:22:42 2017
InstallationDate: Installed on 2016-10-08 (107 days ago)
InstallationMedia: Ubuntu-MATE 16.04.1 LTS "Xenial Xerus" - Release i386 (20160719)
SourcePackage: openscap
UpgradeStatus: No upgrade log present (probably fresh install)
Status changed to 'Confirmed' because the bug affects multiple users.