-
-
Notifications
You must be signed in to change notification settings - Fork 1.2k
Open
Labels
Description
What did you do? (required. The issue will be closed when not provided.)
I ran vuls on redhat 8.6 with curl 7.61.1-22.el8_6.4 installed
What did you expect to happen?
I expected to get 0:7.61.1-22.el8_6.12 as the fixed version
What happened instead?
I got 0:7.61.1-30.el8 as the fixed version
Redhat has a separate oval file for redhat 8.6 EUS
rhel-8.6-eus.oval.xml.bz2
and currently goval-dictionary and vuls does not fetch it and fetch only the redhat 8 oval file and this is causing the FP... as you can see in the redhat security tracker (https://access.redhat.com/security/cve/CVE-2022-35252) they mention 8.6 EUS separately
and I guess vuls should behave according to this