oss-sec mailing list archives
Re: Concerns about CVE coverage shrinking - direct impact to researchers/companies
From: Tim Brown <tmb () 65535 com>
Date: Wed, 09 Mar 2016 15:59:25 +0000
On Sunday 06 March 2016 21:39:54 Gsunde Orangen wrote:
I totally agree. The concern addressed by Kurt initially is fully valid (for both researchers and for companies that are not on Mitre's product/sources list), so a new (better: additional) solution is required. However, creating a new standard independently of CVE would be too disruptive and be a disservice to the software industry.
Quite, as much as I appreciate the options presented over the last few days, I don't think any of them are the winning horse. (To paraphase) if MITRE does not exist then it must be reinvented however the days of multiple competing indexes of vulns should be avoided if possible. We only have to look at the AV community to see how that degenerates. This one of the main reasons that when we open sourced out disclosure tool kit, we explicitly mandated the use of CVEs for tracking.
I'd propose to work out a new solution together with Mitre, whilst keeping the CVE IDs as today.
As would I however, even with pointers from SC about who to poke within MITRE we came up short tracking a warm body down for (~7) months (even one that was willing to say no). That being said, we have now located a new warm body at MITRE who has made themselves known to us, I am more than happy to approach them about the following:
Since 2014, virtually unlimited number of CVE IDs can be assigned per year [1], so a solution could be that - Mitre continues to assign 4 and 5 digit IDs as today - 6 digit IDs are reserved for the new process (hosted outside Mitre) If more than one million vulnerabilities need to be addressed in one year, we could follow the rule (odd digits -> Mitre, even digits -> "other process")From Mitre's POC, this "other process" would become a "CNA", just withits own policy and process definition, not prescribed by Mitre. It would soon become clear to everyone (and all tools and products that rely on CVE) where to look at for the authoritative vulnerability information. And yes: OWASP.org could certainly be a perfect host for that new "CNA" - as Mark offered earlier ;-)
Indeed, such a project requires a vendor neutral host. If OWASP are up for it, then I would gladly support them running with the above proposal, if not then a good faith alternative ought to be sought. Tim -- Tim Brown <mailto:tmb () 65535 com>
Current thread:
- Re: Concerns about CVE coverage shrinking - direct impact to researchers/companies, (continued)
- Re: Concerns about CVE coverage shrinking - direct impact to researchers/companies Rahul Pratap Singh (Mar 06)
- Re: Concerns about CVE coverage shrinking - direct impact to researchers/companies Solar Designer (Mar 06)
- Re: Concerns about CVE coverage shrinking - direct impact to researchers/companies op7ic \x00 (Mar 06)
- Re: Concerns about CVE coverage shrinking - direct impact to researchers/companies Solar Designer (Mar 06)
- Re: Concerns about CVE coverage shrinking - direct impact to researchers/companies op7ic \x00 (Mar 06)
- Re: Concerns about CVE coverage shrinking - direct impact to researchers/companies Solar Designer (Mar 06)
- Re: Concerns about CVE coverage shrinking - direct impact to researchers/companies Robert Paprocki (Mar 06)
- Re: Concerns about CVE coverage shrinking - direct impact to researchers/companies Gsunde Orangen (Mar 06)
- Re: Concerns about CVE coverage shrinking - direct impact to researchers/companies Amos Jeffries (Mar 06)
- RE: [security-vendor] Re: [oss-security] Concerns about CVE coverage shrinking - direct impact to researchers/companies Radzykewycz, T (Radzy) (Mar 07)
- Re: Concerns about CVE coverage shrinking - direct impact to researchers/companies Tim Brown (Mar 09)
- Re: Concerns about CVE coverage shrinking - direct impact to researchers/companies Kurt Seifried (Mar 09)
- Re: Concerns about CVE coverage shrinking - direct impact to researchers/companies David A. Wheeler (Mar 09)
- Re: Concerns about CVE coverage shrinking - direct impact to researchers/companies Kurt Seifried (Mar 09)
- RE: Concerns about CVE coverage shrinking - direct impact to researchers/companies Boyle, Stephen V. (Mar 09)
- RE: Concerns about CVE coverage shrinking - direct impact to researchers/companies John Scott (Mar 10)
- Re: Concerns about CVE coverage shrinking - direct impact to researchers/companies Reed Loden (Mar 09)
- Re: Concerns about CVE coverage shrinking - direct impact to researchers/companies Timothy D. Morgan (Mar 09)
- Re: Concerns about CVE coverage shrinking - direct impact to researchers/companies Kurt Seifried (Mar 09)
- Re: Concerns about CVE coverage shrinking - direct impact to researchers/companies Timothy D. Morgan (Mar 10)
- Re: Concerns about CVE coverage shrinking - direct impact to researchers/companies Kurt Seifried (Mar 10)