False CVE detection for mysql 5.50 #235 adding info message

This commit is contained in:
root 2016-08-31 09:17:03 +02:00
parent 3820a528ed
commit 94c56dad3f

View file

@ -1075,10 +1075,16 @@ sub cve_recommendations {
} }
close $fh or die "Cannot close $opt{cvefile}: $!"; close $fh or die "Cannot close $opt{cvefile}: $!";
$result{'CVE'}{'nb'}=$cvefound; $result{'CVE'}{'nb'}=$cvefound;
my $cve_warning_notes="";
if ( $cvefound == 0 ) { if ( $cvefound == 0 ) {
goodprint "NO SECURITY CVE FOUND FOR YOUR VERSION"; goodprint "NO SECURITY CVE FOUND FOR YOUR VERSION";
return; return;
} }
if ($mysqlvermajor eq 5 and $mysqlverminor eq 7) {
infoprint "False positive CVE(s) for MySQL and MariaDB 5.5.x can be found.";
infoprint "Check careful each CVE for those particular versions";
}
badprint $cvefound . " CVE(s) found for your MySQL release."; badprint $cvefound . " CVE(s) found for your MySQL release.";
push( @generalrec, push( @generalrec,
$cvefound $cvefound