oss-sec mailing list archives

source for CVE feed (was: Re: [oss-security] CVE request: httrack buffer overflow)


From: Thijs Kinkhorst <thijs () debian org>
Date: Mon, 4 Aug 2008 18:58:08 +0200

Hi Steve,

On Monday 4 August 2008 18:37, Steven M. Christey wrote:
It's in NVD but not yet on the public CVE site, due to various process
oddities.  98% of the time, NVD will have the CVEs before the CVE web site
does.

Good to know. Here at Debian we currently import all CVEs into our own system, 
and we use http://cve.mitre.org/data/downloads/allitems.html.gz as the source 
for that.

Considering your statement we would better be using one of the XML Data feeds 
from http://nvd.nist.gov/download.cfm , right? Or would you recommend another 
feed (e.g. the one where NVD gets its data from)?


thanks,
Thijs

Attachment: _bin
Description:


Current thread: