Ubuntu Vulnerability scan is way out.

370 views
Skip to first unread message

Gordon O'Brien

unread,
Aug 20, 2022, 8:39:53 AM8/20/22
to Wazuh mailing list
Hi

I've just installed a new vanilla Ubuntu desktop 22.04 and installed the agent. 
The OS is fully patched yet the vulnerability scanner shows the following:

wazuh-ubuntu-vulnerabilities.png
ossec.conf includes the jammy OS under vulnerability scanning.

I assume this is an error somewhere or is Canonical just really bad at updating?

Thanks for any feedback.


Francisco Tuduri

unread,
Aug 22, 2022, 7:50:28 AM8/22/22
to Wazuh mailing list
Hello Gordon! And thanks for using Wazuh!

I will try to reproduce this in my lab environment and I will get back to you.
Just to be sure, what version of agent and manager are you using?

Regards!

Gordon O'Brien

unread,
Aug 22, 2022, 9:05:52 AM8/22/22
to Wazuh mailing list
Thanks for taking the time to look into this Francisco.
Agent and manager are running 4.3.6

I also have KDE Neon installed  on several machines which are currently still running the Focal LTS base. I've added that as an Alias on Focal and they also show a similarly high number of vulnerabilities:
wazuh-Neon-vulnerabilities.png



Regards
Gordon

Francisco Tuduri

unread,
Aug 22, 2022, 6:32:07 PM8/22/22
to Wazuh mailing list

Would you be willing to share the details of the reported vulnerabilities so we can give them a closer look?
You can export the report as an csv with "Export formatted" option.

Thanks!

Monah Baki

unread,
Aug 23, 2022, 11:13:31 AM8/23/22
to Wazuh mailing list
Hello,


I have the same issue, attached is the reported vulnerabilities exported as csv.

Thanks
Monah
vuls-vulnerabilities.csv

Francisco Tuduri

unread,
Aug 23, 2022, 11:50:45 AM8/23/22
to Wazuh mailing list
Thanks Monah! Is this agent also on Ubuntu 22.04? If not, on what OS is it running?
The cvs file only has "high" vulnerabilities. Could you please export another file with all severity levels?
Thanks again!

Monah Baki

unread,
Aug 23, 2022, 11:58:05 AM8/23/22
to Wazuh mailing list
cat /etc/os-release
PRETTY_NAME="Ubuntu 22.04.1 LTS"
NAME="Ubuntu"
VERSION_ID="22.04"
VERSION="22.04.1 LTS (Jammy Jellyfish)"
VERSION_CODENAME=jammy
ID=ubuntu
ID_LIKE=debian
UBUNTU_CODENAME=jammy
vuls-vulnerabilities(1).csv

Francisco Tuduri

unread,
Aug 23, 2022, 5:26:39 PM8/23/22
to Wazuh mailing list
Gordon, Monah,

Reviewing the list of vulnerabilities provided by Monah, we could see that a very high number, 400 out of 464, of those correspond to the vim package: 2:8.2.3995-1ubuntu2 (vim-common, vim-runtime, vim-tiny, xxd).

We checked the different CVEs that describe those vulnerabilities and effectively that package is currently listed as vulnerable. For example, you can see these two: https://nvd.nist.gov/vuln/detail/CVE-2022-2304, https://nvd.nist.gov/vuln/detailCVE-2022-2207.

In summary, the high number of vulnerabilities reported are valid but are also mostly related to that one package.

Gordon,

We don't have the report of your vulnerabilities, but I installed a fresh Ubuntu 22.04.1 and my results were very similar to yours, and found the same scenario described above. So my guess is that that is also what is happening in your case. You can check if a high number of you vulnerabilities belong to version '2:8.2.3995-1ubuntu2'. If that is not the case let us know and we will give them a look.

Regards!

Gordon O'Brien

unread,
Aug 23, 2022, 5:39:33 PM8/23/22
to Francisco Tuduri, Wazuh mailing list
I'm afraid I am away for a few days so cannot get the report just yet. However I suspect it will be very similar to that supplied by Monah.
So I'd I understand you correctly, this is mainly due to Canonical not patching these few packages? 

Thanks 
Gordon

Sent from Nine

From: Francisco Tuduri <francisc...@wazuh.com>
Sent: Tuesday, 23 August 2022 22:26
To: Wazuh mailing list
Subject: Re: Ubuntu Vulnerability scan is way out.
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.

Francisco Tuduri

unread,
Aug 23, 2022, 6:38:37 PM8/23/22
to Wazuh mailing list
Yes, that's right.
And if you don't need vim (or just want to try) you can remove those packages and the bulk of those vulnerabilities should go away.
Regards!
Reply all
Reply to author
Forward
0 new messages