oss-sec mailing list archives
Re: MITRE is adding data intake to its CVE ID process
From: Seth Arnold <seth.arnold () canonical com>
Date: Fri, 10 Feb 2017 12:59:16 -0800
On Fri, Feb 10, 2017 at 03:40:45PM +0000, Priedhorsky, Reid wrote:
I’ve been using the CVE requests on oss-security to maintain a reasonably comprehensive and timely list of vulnerabilities for specific products. It’s not clear to me how to do this when CVE requests happen offline in a web form. Has this use case been considered? Is there an alternate way to accomplish my goal?
Another part of the email from MITRE included "When you enter a vulnerability description on the web form, the CVE and description will typically be available on the NVD and CVE web sites at the same time or shortly after we email the CVE ID to you." While the oss-security list has been the best resource of information for CVEs for us, part of our CVE ingestion is to download data from NVD and MITRE directly: https://nvd.nist.gov/download https://cve.mitre.org/data/downloads/allitems.xml Debian's database is also very useful to us: https://anonscm.debian.org/viewvc/secure-testing/data/CVE/ And of course our database is freely available as well: https://code.launchpad.net/~ubuntu-security/ubuntu-cve-tracker/master I hope this can help you adapt your processes as MITRE adapts theirs. Thanks
Attachment:
signature.asc
Description:
Current thread:
- Re: MITRE is adding data intake to its CVE ID process, (continued)
- Re: MITRE is adding data intake to its CVE ID process Priedhorsky, Reid (Feb 10)
- Re: MITRE is adding data intake to its CVE ID process John Haxby (Feb 10)
- Re: MITRE is adding data intake to its CVE ID process Stiepan (Feb 10)
- Re: MITRE is adding data intake to its CVE ID process Simon McVittie (Feb 10)
- Re: MITRE is adding data intake to its CVE ID process Pierre Schweitzer (Feb 10)
- Re: MITRE is adding data intake to its CVE ID process Moritz Muehlenhoff (Feb 11)
- Re: MITRE is adding data intake to its CVE ID process Bob Friesenhahn (Feb 11)
- Re: MITRE is adding data intake to its CVE ID process John Haxby (Feb 10)
- Re: MITRE is adding data intake to its CVE ID process Priedhorsky, Reid (Feb 10)
- RE: MITRE is adding data intake to its CVE ID process Maier, Kurt H (Feb 10)
- RE: MITRE is adding data intake to its CVE ID process Ben Tasker (Feb 10)
- Re: MITRE is adding data intake to its CVE ID process Mike Gerwitz (Feb 10)
- Re: MITRE is adding data intake to its CVE ID process Seth Arnold (Feb 10)
- RE: MITRE is adding data intake to its CVE ID process Maier, Kurt H (Feb 10)
- Re: MITRE is adding data intake to its CVE ID process Tim (Feb 10)
- Re: MITRE is adding data intake to its CVE ID process Kurt Seifried (Feb 10)
- RE: MITRE is adding data intake to its CVE ID process Williams, Ken (Feb 10)
- Re: MITRE is adding data intake to its CVE ID process Mats Wichmann (Feb 10)
- Re: MITRE is adding data intake to its CVE ID process Tim (Feb 10)
- Re: MITRE is adding data intake to its CVE ID process Adam Caudill (Feb 10)
- Re: MITRE is adding data intake to its CVE ID process Tim (Feb 10)
- Re: MITRE is adding data intake to its CVE ID process Guido Berhoerster (Feb 10)