Hi,

I've seen a same type of error with SSG 0.1.32 when using OpenSCAP release 1.0.9 (Debian Jessie release). That's why by now the ssg package for Debian is still using 0.1.31 - same message but whithout the SIGSEGV). I've never seen this bug with 1.2.x version of OpenSCAP.

What is strange is the fact that the second scan just works fine. The two executions are normally independantly executed, without any interactions.

You precised that the target uses libopenscap8 release 1.2.9-1, which means that you backported the Stretch release on Jessie ?

Have you tried other scans to check if there is no more bug or if it happends heratically ?


Le 27/04/2017 à 12:23, Luther Goh Lu Feng a écrit :
Running a from a debian scanner, to scan a debian target using openscap-ssh, 
first time scan results in the error below.

Command is:
ssh -t debian@192.168.0.1 "~/oscap-ssh/oscap-ssh root@192.168.0.2 22  xccdf eval 
--fetch-remote-resources --results ~/scan/debian-xccdf-results.xml --report 
~/scan/debian-xccdf-results.html --profile xccdf_org.ssgproject.content_profile_common 
/usr/share/ssg/ssg-debian8-ds.xml";

Scanner libaries:
libopenscap8                         1.2.9-1+b2
ssg-debian                           0.1.31-3


Target libraries:
libopenscap8                         1.2.9-1+b2

Second scan results in no error. Is this a known bug or is there a 
misconfiguration somewhere?


===============
OpenSCAP Error: Probe with PID=6497 has been killed with signal 11 
[../../../../../src/OVAL/probes/SEAP/sch_pipe.c:173]
Item corresponding to object 'oval:ssg-obj_package_rsyslog_installed:obj:1' 
from test 'oval:ssg-test_package_rsyslog_installed:tst:1' has an unknown flag. 
This may indicate a bug in OpenSCAP. 
[../../../../src/OVAL/results/oval_resultTest.c:908]
Probe with PID=6509 has been killed with signal 11 
[../../../../../src/OVAL/probes/SEAP/sch_pipe.c:173]
Item corresponding to object 'oval:ssg-obj_package_telnetd_removed:obj:1' from 
test 'oval:ssg-test_package_telnetd_removed:tst:1' has an unknown flag. This 
may indicate a bug in OpenSCAP. 
[../../../../src/OVAL/results/oval_resultTest.c:908]
Probe with PID=6515 has been killed with signal 11 
[../../../../../src/OVAL/probes/SEAP/sch_pipe.c:173]
Item corresponding to object 
'oval:ssg-obj_package_inetutils-telnetd_removed:obj:1' from test 
'oval:ssg-test_package_inetutils-telnetd_removed:tst:1' has an unknown flag. 
This may indicate a bug in OpenSCAP. 
[../../../../src/OVAL/results/oval_resultTest.c:908]
Probe with PID=6523 has been killed with signal 11 
[../../../../../src/OVAL/probes/SEAP/sch_pipe.c:173]
Item corresponding to object 'oval:ssg-obj_package_telnetd-ssl_removed:obj:1' 
from test 'oval:ssg-test_package_telnetd-ssl_removed:tst:1' has an unknown 
flag. This may indicate a bug in OpenSCAP. 
[../../../../src/OVAL/results/oval_resultTest.c:908]
Probe with PID=6529 has been killed with signal 11 
[../../../../../src/OVAL/probes/SEAP/sch_pipe.c:173]
Item corresponding to object 'oval:ssg-obj_package_nis_removed:obj:1' from test 
'oval:ssg-test_package_nis_removed:tst:1' has an unknown flag. This may 
indicate a bug in OpenSCAP. [../../../../src/OVAL/results/oval_resultTest.c:908]
Probe with PID=6535 has been killed with signal 11 
[../../../../../src/OVAL/probes/SEAP/sch_pipe.c:173]
Item corresponding to object 'oval:ssg-obj_package_ntpdate_removed:obj:1' from 
test 'oval:ssg-test_package_ntpdate_removed:tst:1' has an unknown flag. This 
may indicate a bug in OpenSCAP. 
[../../../../src/OVAL/results/oval_resultTest.c:908]
Probe with PID=6541 has been killed with signal 11 
[../../../../../src/OVAL/probes/SEAP/sch_pipe.c:173]
Item corresponding to object 'oval:ssg-obj_package_auditd_installed:obj:1' from 
test 'oval:ssg-test_package_auditd_installed:tst:1' has an unknown flag. This 
may indicate a bug in OpenSCAP. 
[../../../../src/OVAL/results/oval_resultTest.c:908]
Probe with PID=6547 has been killed with signal 11 
[../../../../../src/OVAL/probes/SEAP/sch_pipe.c:173]
Item corresponding to object 'oval:ssg-obj_package_cron_installed:obj:1' from 
test 'oval:ssg-test_package_cron_installed:tst:1' has an unknown flag. This may 
indicate a bug in OpenSCAP. [../../../../src/OVAL/results/oval_resultTest.c:908]
Probe with PID=6553 has been killed with signal 11 
[../../../../../src/OVAL/probes/SEAP/sch_pipe.c:173]
Item corresponding to object 'oval:ssg-obj_package_ntp_installed:obj:1' from 
test 'oval:ssg-test_package_ntp_installed:tst:1' has an unknown flag. This may 
indicate a bug in OpenSCAP. [../../../../src/OVAL/results/oval_resultTest.c:908]
Probe with PID=6559 has been killed with signal 11 
[../../../../../src/OVAL/probes/SEAP/sch_pipe.c:173]
Item corresponding to object 
'oval:ssg-obj_package_openssh-server_removed:obj:1' from test 
'oval:ssg-test_package_openssh-server_removed:tst:1' has an unknown flag. This 
may indicate a bug in OpenSCAP. 
[../../../../src/OVAL/results/oval_resultTest.c:908]
Result  pass

oscap exit code: 2

_______________________________________________
Open-scap-list mailing list
Open-scap-list@redhat.com
https://www.redhat.com/mailman/listinfo/open-scap-list

_______________________________________________
Open-scap-list mailing list
Open-scap-list@redhat.com
https://www.redhat.com/mailman/listinfo/open-scap-list

Reply via email to