<?xml version="1.0" encoding="utf-8"?>
<?xml-stylesheet type="text/css" href="http://brandonhutchinson.com/mediawiki/skins/common/feed.css?97"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
	<channel>
		<title>RPMs and CVEs - Revision history</title>
		<link>http://brandonhutchinson.com/mediawiki/index.php5?title=RPMs_and_CVEs&amp;action=history</link>
		<description>Revision history for this page on the wiki</description>
		<language>en</language>
		<generator>MediaWiki 1.11.0rc1</generator>
		<lastBuildDate>Tue, 21 May 2013 08:58:07 GMT</lastBuildDate>
		<item>
			<title>Hutch at 15:34, 4 September 2009</title>
			<link>http://brandonhutchinson.com/mediawiki/index.php5?title=RPMs_and_CVEs&amp;diff=1449&amp;oldid=prev</link>
			<description>&lt;p&gt;&lt;/p&gt;

			&lt;table style=&quot;background-color: white; color:black;&quot;&gt;
			&lt;col class='diff-marker' /&gt;
			&lt;col class='diff-content' /&gt;
			&lt;col class='diff-marker' /&gt;
			&lt;col class='diff-content' /&gt;
			&lt;tr&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black;&quot;&gt;←Older revision&lt;/td&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black;&quot;&gt;Revision as of 15:34, 4 September 2009&lt;/td&gt;
			&lt;/tr&gt;
		&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 6:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 6:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;Note that starting on 2005/10/19, the ''CAN-'' prefix is no longer used for candidate CVE entries. It should be included in the above search for any 2005 or earlier CVE's.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;Note that starting on 2005/10/19, the ''CAN-'' prefix is no longer used for candidate CVE entries. It should be included in the above search for any 2005 or earlier CVE's.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;nbsp;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;nbsp;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;If the CVE's are not found in the package changelog, check the below ''Red Hat vulnerabilities by CVE name'' link for more information on how the CVE affects Red Hat products.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;== Links ==&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;== Links ==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</description>
			<pubDate>Fri, 04 Sep 2009 15:34:09 GMT</pubDate>			<dc:creator>Hutch</dc:creator>			<comments>http://brandonhutchinson.com/wiki/Talk:RPMs_and_CVEs</comments>		</item>
		<item>
			<title>Hutch: /* Links */</title>
			<link>http://brandonhutchinson.com/mediawiki/index.php5?title=RPMs_and_CVEs&amp;diff=1448&amp;oldid=prev</link>
			<description>&lt;p&gt;&lt;span class=&quot;autocomment&quot;&gt;Links&lt;/span&gt;&lt;/p&gt;

			&lt;table style=&quot;background-color: white; color:black;&quot;&gt;
			&lt;col class='diff-marker' /&gt;
			&lt;col class='diff-content' /&gt;
			&lt;col class='diff-marker' /&gt;
			&lt;col class='diff-content' /&gt;
			&lt;tr&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black;&quot;&gt;←Older revision&lt;/td&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black;&quot;&gt;Revision as of 15:33, 4 September 2009&lt;/td&gt;
			&lt;/tr&gt;
		&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 12:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 12:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;* [http://www.redhat.com/security/transparent/cve/ Red Hat and CVE Compatibility]&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;* [http://www.redhat.com/security/transparent/cve/ Red Hat and CVE Compatibility]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;* [http://www.redhat.com/security/transparent/oval/ Red Hat and OVAL compatibility]&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;* [http://www.redhat.com/security/transparent/oval/ Red Hat and OVAL compatibility]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;nbsp;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;* [https://www.redhat.com/security/data/cve/ Red Hat vulnerabilities by CVE name]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</description>
			<pubDate>Fri, 04 Sep 2009 15:33:06 GMT</pubDate>			<dc:creator>Hutch</dc:creator>			<comments>http://brandonhutchinson.com/wiki/Talk:RPMs_and_CVEs</comments>		</item>
		<item>
			<title>Hutch: New page: Vulnerability Assessment (VA) tools commonly flag services on our Red Hat systems as potentially vulnerable based on the services' versions alone. Since Red Hat [http://www.redhat.com/secu...</title>
			<link>http://brandonhutchinson.com/mediawiki/index.php5?title=RPMs_and_CVEs&amp;diff=437&amp;oldid=prev</link>
			<description>&lt;p&gt;New page: Vulnerability Assessment (VA) tools commonly flag services on our Red Hat systems as potentially vulnerable based on the services' versions alone. Since Red Hat [http://www.redhat.com/secu...&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;Vulnerability Assessment (VA) tools commonly flag services on our Red Hat systems as potentially vulnerable based on the services' versions alone. Since Red Hat [http://www.redhat.com/security/updates/backporting/ backports] security fixes into its packages, the packages may already be patched to address the vulnerabilities. Note that VA tools that support the [http://www.redhat.com/security/transparent/oval/ Open Vulnerability and Assessment Language (OVAL)] can determine the status of vulnerabilities even with backported fixes.&lt;br /&gt;
&lt;br /&gt;
VA tools often refererence vulnerabilities by their [http://en.wikipedia.org/wiki/Common_Vulnerabilities_and_Exposures Common Vulnerabilities and Exposures (CVE)] number. One of the easiest ways to determine if a Red Hat package is patched for a particular CVE is to examine the package's ''changelog''.&lt;br /&gt;
&lt;br /&gt;
 $ '''rpm -q ''package'' --changelog | egrep &amp;quot;(CAN|CVE)-&amp;quot;'''&lt;br /&gt;
&lt;br /&gt;
Note that starting on 2005/10/19, the ''CAN-'' prefix is no longer used for candidate CVE entries. It should be included in the above search for any 2005 or earlier CVE's.&lt;br /&gt;
&lt;br /&gt;
== Links ==&lt;br /&gt;
&lt;br /&gt;
* [http://www.redhat.com/security/updates/backporting/ Backporting of Security Fixes]&lt;br /&gt;
* [http://www.redhat.com/security/transparent/cve/ Red Hat and CVE Compatibility]&lt;br /&gt;
* [http://www.redhat.com/security/transparent/oval/ Red Hat and OVAL compatibility]&lt;/div&gt;</description>
			<pubDate>Fri, 05 Oct 2007 19:33:10 GMT</pubDate>			<dc:creator>Hutch</dc:creator>			<comments>http://brandonhutchinson.com/wiki/Talk:RPMs_and_CVEs</comments>		</item>
	</channel>
</rss>