Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

False Positive: CVE-2005-2945, CVE-2005-2992 #1139

Closed
sekveaja opened this issue Feb 21, 2023 · 2 comments
Closed

False Positive: CVE-2005-2945, CVE-2005-2992 #1139

sekveaja opened this issue Feb 21, 2023 · 2 comments
Labels
changelog-ignore Don't include this issue in the release changelog false-positive

Comments

@sekveaja
Copy link

What happened:
Issue with  "package_cpe23": "cpe:2.3:a:quarkus:arc:2.7.6.Final-nordix-1:::::::*",

But Grype reported to version 5.21j  which is not the same package
 cpe:2.3:a:arc:arc:::::::: 

quarkus:arc is not arc:arc

Environment:
Anchore Grype version: 0.56.0

OS type running in the current environment i.e. (cat /etc/os-release)

cat /etc/os-release
NAME="SLES"
VERSION="15-SP3"
VERSION_ID="15.3"
PRETTY_NAME="SUSE Linux Enterprise Server 15 SP3"
ID="sles"
ID_LIKE="suse"
ANSI_COLOR="0;32"
CPE_NAME="cpe:/o:suse:sles:15:sp3"
DOCUMENTATION_URL="https://documentation.suse.com/"

@sekveaja sekveaja added the bug Something isn't working label Feb 21, 2023
@sekveaja sekveaja changed the title False Positive: CVE-2005-2945 False Positive: CVE-2005-2945, CVE-2005-2992 Apr 14, 2023
@kzantow
Copy link
Contributor

kzantow commented Jul 18, 2024

Hi, and apologies for the delay. We're going over old issues and wanted to see:

  1. is this still an issue with the latest version of Grype?
  2. are there steps you could provide to reproduce this?

Thanks!

@sekveaja
Copy link
Author

We update our product from SLES 15 SP3 with SLES 15 SP5, at the same time Grype has evolved also.
The reported CVE is no longer shown.
You can closed this ticket.
Thank you

@willmurphyscode willmurphyscode added changelog-ignore Don't include this issue in the release changelog and removed bug Something isn't working labels Oct 5, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
changelog-ignore Don't include this issue in the release changelog false-positive
Projects
Archived in project
Development

No branches or pull requests

3 participants