oss-sec mailing list archives
Re: CVE? CCE? dovecot setting is often used incorrectly
From: "Steven M. Christey" <coley () linus mitre org>
Date: Sun, 9 Mar 2008 19:51:28 -0400 (EDT)
On Tue, 4 Mar 2008, Jonathan Smith wrote:
I've been trying to figure out what to do with this one. I'm not inclined to believe it deserves a CVE given that it is configuration (either dovecot config or filesystem permissions configuration). I read once on mitre.org about "Common Configuration Enumeration" aka "CCE" issues, but I've never seen them actually used. Maybe this is a good candidate? Steve, any ideas?
Sorry for the delayed response - had some computer problems just as I was about to press "send" and forgot about this. CCE is gaining a lot of ground these days as part of the US government's SCAP program for enterprise-level security information management (summarizing SCAP approximately at best). We've identified some areas of potential overlap where both CCE and CVE could apply. At this stage though, CCE is mostly about configuration/hardening at the OS layer, including major OS applications - that said, conceptually it could apply to any application. Especially in cases where a "non-OS-level" application has a default configuration, or where a bug introduces a configuration issue, CVE continues to assign identifiers. We'll also assign an identifier for a common misconfiguration, even if it's not the default. So - use CVE-2008-1199 for this issue. - Steve
Current thread:
- CVE? CCE? dovecot setting is often used incorrectly Jonathan Smith (Mar 04)
- Re: CVE? CCE? dovecot setting is often used incorrectly Florian Weimer (Mar 08)
- Re: CVE? CCE? dovecot setting is often used incorrectly Robert Buchholz (Mar 08)
- Re: CVE? CCE? dovecot setting is often used incorrectly Steven M. Christey (Mar 09)
- Re: CVE? CCE? dovecot setting is often used incorrectly Florian Weimer (Mar 08)