oss-sec mailing list archives
Dealing with CVEs that apply to unspecified package versions
From: ludo () gnu org (Ludovic Courtès)
Date: Wed, 15 Mar 2017 18:12:52 +0100
Hello, Some CVE entries do not specify the version of the package(s) they apply to. For instance, the software list for CVE-2016-10165 contains “cpe:/a:littlecms:little_cms_color_engine”, which theoretically means that it applies to any version of lcms. The problem is automated tools cannot exploit such entries in practice because they cannot tell which package versions are affected. While tuning our CVE tracking tool in GNU Guix, we found that such entries are not uncommon: https://lists.gnu.org/archive/html/guix-devel/2017-03/msg00335.html What are the possibilities to address this issue? I can think of two actions that could perhaps be taken: 1. The software behind the CVE form could force submitters to specify version numbers. 2. For recent entries (say, 2 years old at most), a bot could email the original submitters kindly asking them to provide the missing version info. Thoughts? Thanks, Ludo’.
Current thread:
- Dealing with CVEs that apply to unspecified package versions Ludovic Courtès (Mar 15)
- Re: Dealing with CVEs that apply to unspecified package versions Simon McVittie (Mar 15)
- Re: Dealing with CVEs that apply to unspecified package versions Seth Arnold (Mar 15)
- Re: Dealing with CVEs that apply to unspecified package versions Leo Famulari (Mar 15)
- Re: Dealing with CVEs that apply to unspecified package versions Kurt Seifried (Mar 15)
- Re: Dealing with CVEs that apply to unspecified package versions Jerome Athias (Mar 16)
- Re: Dealing with CVEs that apply to unspecified package versions Jerome Athias (Mar 16)
- Re: Dealing with CVEs that apply to unspecified package versions Leo Famulari (Mar 15)
- Re: Dealing with CVEs that apply to unspecified package versions Jerome Athias (Mar 18)