Forum Discussion
RPM-Package Detection Improvements Summary Tenable’s RPM-base
RPM-Package Detection Improvements
Summary
Tenable’s RPM-based version checks are being enhanced with more accurate detection logic.
Target Release Date
November 6 8 13, 2023
Change
A common library used in Tenable’s RPM-based detection plugins will be modified to no longer constrain version checks to the specific major version of the fixed package. Under the legacy approach, there was a possibility of false negatives in cases where the distribution maintainers bump the major version number of a package within a single operating system release.
Impact
This change may result in a small increase in the number of findings for some customers running RPM-based OS distributions. Specifically in scenarios where packages are significantly out of date relative to the latest version, and in the course of those version updates, the major version number of the package changes.
2 Replies
- zcerkovnikEmployee
The Target Release Date for this improvement has been moved to Wednesday, November 8th.
- zcerkovnikEmployee
Due to the upcoming US holiday on Friday, November 10, this release has been pushed to Monday, November 13th.