<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<style type="text/css" style="display:none;"><!-- P {margin-top:0;margin-bottom:0;} --></style>
</head>
<body dir="ltr">
<div id="divtagdefaultwrapper" style="font-size:12pt;color:#000000;font-family:Calibri,Helvetica,sans-serif;" dir="ltr">
<p style="margin-top:0;margin-bottom:0">I apologize for the delayed response, I was tasked with an urgent request right after sending this.  Thank you for your reply and the good information it provided.</p>
</div>

<P id=c1-id-7 
style="FONT-SIZE: 0px; FONT-FAMILY: Arial; COLOR: #fff">Harriscomputer</P>
<TABLE id=c1-id-8 
style="BORDER-LEFT-WIDTH: 0px; BORDER-RIGHT-WIDTH: 0px; BORDER-BOTTOM-WIDTH: 0px; PADDING-BOTTOM: 0px; PADDING-TOP: 0px; PADDING-LEFT: 0px; MARGIN: 0px; PADDING-RIGHT: 0px; BORDER-TOP-WIDTH: 0px">
  <COLGROUP id=c1-id-9>
  <COL id=c1-id-10></COL></COLGROUP>
  <TBODY id=c1-id-11>
  <TR id=c1-id-12>
    <TD id=c1-id-13>
      <TABLE id=c1-id-14 style="HEIGHT: 0px; WIDTH: 100%" cellSpacing=0 
      cellPadding=0 border=0>
        <COLGROUP id=c1-id-15>
        <COL id=c1-id-16>
        <COL id=c1-id-17>
        <COL id=c1-id-18></COL></COL></COL></COLGROUP>
        <TBODY id=c1-id-19>
        <TR id=c1-id-27>
          <TD id=c1-id-28 style="WIDTH: 33%">
            <P style="FONT-SIZE: 10pt; FONT-FAMILY: Arial" align=left><B 
            id=c1-id-30><FONT id=c1-id-31 face=Arial>Leroy Tennison<BR 
            id=c1-id-32></FONT></B><FONT id=c1-id-33 size=2 
            face=Arial>Network Information/Cyber Security Specialist<BR id=c1-id-38><SPAN id=c1-id-39 
            style="FONT-SIZE: 8pt">E: leroy@datavoiceint.com</SPAN></FONT></P></TD>
          <TD id=c1-id-40 style="WIDTH: 33%">
            <P style="FONT-SIZE: 10pt; FONT-FAMILY: Arial; TEXT-ALIGN: center" 
            align=center><BR id=c1-id-43><IMG border=0 
            src="cid:Data-Voice-International-LOGO_aa3d1c6e-5cfb-451f-ba2c-af8059e69609.PNG"></P></TD>
          <TD id=c1-id-45 style="WIDTH: 33%">
            <P id=c1-id-46 
            style="FONT-SIZE: 10pt; FONT-FAMILY: Arial; TEXT-ALIGN: right" 
            align=right><FONT id=c1-id-47 style="FONT-SIZE: 8pt" 
            face=Arial>2220 Bush Dr<BR id=c1-id-48>McKinney, Texas<BR 
            id=c1-id-49>75070<BR><FONT id=c1-id-51 
            style="FONT-SIZE: 8pt" face=Arial><A 
            href="http://www..com">www.datavoiceint.com</A></FONT></FONT><FONT 
            id=c1-id-56 size=3> </FONT></P></TD></TR></TBODY></TABLE>
      <TABLE id=c1-id-57 style="WIDTH: 100%" cellSpacing=2 border=0>
        <COLGROUP id=c1-id-58>
        <COL id=c1-id-59>
        <COL id=c1-id-60>
        <COL id=c1-id-61></COL></COL></COL></COLGROUP>
        <TBODY id=c1-id-62>
        <TR id=c1-id-63>
          <TD id=c1-id-64 colSpan=3>
            <P id=c1-id-65 
            style="MARGIN-BOTTOM: 0px; FONT-SIZE: 10pt; FONT-FAMILY: Arial; MARGIN-TOP: 0px"><FONT 
            id=c1-id-66 size=1 face=Arial>This message has been sent on behalf 
            of a company that is part of the Harris Operating Group of 
            Constellation Software Inc. These companies are listed <A 
            href="http://subscribe.harriscomputer.com/">here</A>. </FONT></P>
            <P 
            style="MARGIN-BOTTOM: 0px; FONT-SIZE: 10pt; FONT-FAMILY: Arial; MARGIN-TOP: 0px"><FONT 
            size=1 face=Arial>If you prefer not to be contacted by Harris 
            Operating Group <A 
            href="http://subscribe.harriscomputer.com/">please notify us</A>. 
            </FONT></P>
            <P 
            style="MARGIN-BOTTOM: 0px; FONT-SIZE: 10pt; FONT-FAMILY: Arial; MARGIN-TOP: 0px"> </P>
            <P 
            style="MARGIN-BOTTOM: 0px; FONT-SIZE: 10pt; FONT-FAMILY: Arial; MARGIN-TOP: 0px"><FONT 
            size=1 face=Arial></FONT></P>
            <P 
            style="MARGIN-BOTTOM: 0px; FONT-SIZE: 10pt; FONT-FAMILY: Arial; MARGIN-TOP: 0px"><FONT 
            size=1 face=Arial>This message is intended exclusively for the 
            individual or entity to which it is addressed. This communication 
            may contain information that is proprietary, privileged or 
            confidential or otherwise legally exempt from disclosure. If you are 
            not the named addressee, you are not authorized to read, print, 
            retain, copy or disseminate this message or any part of it. If you 
            have received this message in error, please notify the sender 
            immediately by e-mail and delete all copies of the 
            message.</FONT></P></TD></TR></TBODY></TABLE></TD></TR></TBODY></TABLE>
<P id=c1-id-74 
style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"> </P><hr style="display:inline-block;width:98%" tabindex="-1">
<div id="divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" style="font-size:11pt" color="#000000"><b>From:</b> Rafael David Tinoco <rafaeldtinoco@ubuntu.com><br>
<b>Sent:</b> Friday, June 7, 2019 12:35:02 PM<br>
<b>To:</b> Leroy Tennison; ubuntu-server@lists.ubuntu.com<br>
<b>Subject:</b> [EXTERNAL] Re: Is there an official statement about the Ubuntu package version identifier</font>
<div> </div>
</div>
<div class="BodyFragment"><font size="2"><span style="font-size:11pt;">
<div class="PlainText">Hello Leroy<br>
<br>
On 06/06/2019 16:03, Leroy Tennison wrote:<br>
> The reason I ask is I have a commercial vulnerability scanner reporting<br>
> as "fail" a test (for example, CVE-2016-5387)of our<br>
> systems where <a href="https://linkprotect.cudasvc.com/url?a=https%3a%2f%2fpeople.canonical.com%2f~ubuntu-security%2fcve%2f%c2%a0states&c=E,1,tkTlppPgv7BOXN3x5klrMGABIMPZ7MTaXnKwoYnURJVt_eTHEc8CFMCgyC6eLOuO0xJxj4HiRNUrila9NO7mIGZ1Wo-yva6eLJ5OaRksTgAH-kqIBw,,&typo=1">https://linkprotect.cudasvc.com/url?a=https%3a%2f%2fpeople.canonical.com%2f~ubuntu-security%2fcve%2f%c2%a0states&c=E,1,tkTlppPgv7BOXN3x5klrMGABIMPZ7MTaXnKwoYnURJVt_eTHEc8CFMCgyC6eLOuO0xJxj4HiRNUrila9NO7mIGZ1Wo-yva6eLJ5OaRksTgAH-kqIBw,,&typo=1</a><br>
> that a fix has been released and our current version appears to be later<br>
> than that release.  I need to dispute that finding for compliance<br>
> reasons but would like an official statement to show to the vendor<br>
> concerning how Ubuntu handles these things.  I suspect the vendor is<br>
> only checking the upstream major and minor version number rather than<br>
> actually testing and thus concluding a "fail" erroneously.<br>
<br>
2 good resources about versioning can be found here:<br>
<br>
Debian versioning:<br>
<br>
<a href="https://www.debian.org/doc/debian-policy/ch-controlfields.html#version">https://www.debian.org/doc/debian-policy/ch-controlfields.html#version</a><br>
<br>
A blog entry from Robie basak, explaining Ubuntu versioning in details:<br>
<br>
<a href="https://linkprotect.cudasvc.com/url?a=http%3a%2f%2fwww.justgohome.co.uk%2fblog%2f2015%2f01%2fubuntu-package-versions.html&c=E,1,zprTYA8GmUjXzAXeLr65RNOcLymTKv8YKDT_nujlxA3SOe_DX6kUSElH0CrHkbCHuc0GyhQSJi208QDtWUb0LbJ6sY26kt1ZXT010LxcYg,,&typo=1">https://linkprotect.cudasvc.com/url?a=http%3a%2f%2fwww.justgohome.co.uk%2fblog%2f2015%2f01%2fubuntu-package-versions.html&c=E,1,zprTYA8GmUjXzAXeLr65RNOcLymTKv8YKDT_nujlxA3SOe_DX6kUSElH0CrHkbCHuc0GyhQSJi208QDtWUb0LbJ6sY26kt1ZXT010LxcYg,,&typo=1</a><br>
<br>
A good way of making sure a version is greater than other is to execute:<br>
<br>
dpkg --compare-versions 1ubuntu1.0-1 gt 1ubuntu1.0~1 && echo greater<br>
than || echo less than<br>
<br>
and check.<br>
</div>
</span></font></div>
</body>
</html>