4 ms·
Eh, it just seems to compare detected versions against the latest version of software. It would be nice if it said why the installed version is vulnerable, lin
by RossM 11y ago
Eh, it just seems to compare detected versions against the latest version of software. It would be nice if it said why the installed version is vulnerable, links to CVEs, etc.
- dolfje 11y agoWe indeed compare versions against the latest version of the software. Though we also keep track of which versions are supported and also create an inventory with the CVEs and their risk. There are also vulnerability scanners incorporated. That is why we sometimes still show a version is outdated, while we don't know the actual version. For now we spend more time into giving information on how to keep your system secure and make that as easy as possible. If we can present 1 solution to fix 22 cve exploits, we find that preferable to showing 22 issues that need to get fixed with detailed information about the cve. But should that data should still be findable for experts and is also shown our the data cards. (Except when the data isn't disclosed yet by the software manufacturer) So if you don't see the CVE, please tell us more details about the software that doesn't has vulnerabilities.
- RossM 11y agoOkay, that sounds more worthwhile. When I did a simple test against a LAMP server, the only information I got back was "running 5.5.25, latest 5.5.27, this is a vulnerability". I assume you're presenting that info for different software.
- dolfje 11y agoThere is more logic to it. We try to detect if you use ubuntu/debian and suggest those updates. From the moment we know the exploits, we show them. Probably you're talking about PHP? For PHP 5.5.25 there are the following exploits CVE-2015-3414, CVE-2015-3415, CVE-2015-3416, CVE-2015-2325, CVE-2015-2326 and CVE-2015-3152. But none of them have information yet. (see https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3152 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3152) So as soon as they are disclosed, the exploits will automatically be shown (within 5 minutes)