Wednesday, January 17, 2018

Solaris 11: CVE Management

Solaris 11 Critical Patch Update package to make it easier for you to install and track fixes for Criticial Vulnerabilities and Exposures (CVE).
Once you've installed the package (pkg install solaris-11-cpu), applying all available Solaris fixes for CVE is now as simple as:
# pkg update solaris-11-cpu

Solaris 11: pkg command

https://docs.oracle.com/cd/E53394_01/html/E54817/cvepkg.html

# pkg search CVE-2014-7187:

Verifying That the Latest CPU Is Installed
To determine the status of the latest solaris-11-cpu package, use the pkg list command.
$ pkg list -af solaris-11-cpu@latest
NAME (PUBLISHER)                                  VERSION                    IFO
support/critical-patch-update/solaris-11-cpu      2015.8-1                   ---
 
 Verifying That a Fix for a CVE ID Is Installed
      
To verify that you installed a fix for a specific CVE ID, search your installed packages for the CVE ID. If it is not installed, no output displays. The pkg search -l command searches the local disk only.
# pkg search -l CVE-2014-7187 INDEX ACTION VALUE PACKAGE info.cve set CVE-2014-7187 pkg:/support/critical-patch-update/solaris-11-cpu@2014.10-1


 
 # pkg list -af entire