oss-sec mailing list archives

Re: MITRE is adding data intake to its CVE ID process


From: Henri Salo <henri () nerv fi>
Date: Wed, 15 Feb 2017 10:28:22 +0200

On Mon, Feb 13, 2017 at 04:40:29PM +0000, Priedhorsky, Reid wrote:
However, our understanding of CVE consumers is that they look to MITRE as a
source of vulnerability information after a CVE ID number exists, not before.

Lots of users are also fetching the CVE database and try to match it with their
installed software to get notified of new vulnerabilities affecting their infra
and used products.

-- 
Henri Salo


Current thread: