<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugzilla.yoctoproject.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.6"
          urlbase="https://bugzilla.yoctoproject.org/"
          
          maintainer="it-coreprojects-helpdesk@linuxfoundation.org"
>

    <bug>
          <bug_id>13001</bug_id>
          
          <creation_ts>2018-11-09 12:59:09 +0000</creation_ts>
          <short_desc>Need to consider how to handle triage for reserved CVEs</short_desc>
          <delta_ts>2019-01-12 18:30:33 +0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>6</classification_id>
          <classification>Yocto Project Subprojects</classification>
          <product>Security Response Tool</product>
          <component>General</component>
          <version>unspecified</version>
          <rep_platform>x86</rep_platform>
          <op_sys>Multiple</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>Medium</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>2.7</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Ross Burton">ross.burton</reporter>
          <assigned_to name="David Reyna">david.reyna</assigned_to>
          
          
          
          <cf_os>---</cf_os>
          <cf_regression_type>---</cf_regression_type>
          
          <cf_docchange>No (bug/feature does not impact docs)</cf_docchange>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>82112</commentid>
    <comment_count>0</comment_count>
    <who name="Ross Burton">ross.burton</who>
    <bug_when>2018-11-09 12:59:09 +0000</bug_when>
    <thetext>CVE-2018-10195 is &apos;reserved&apos; at MITRE:

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10195

However Red Has has lots of details:

https://access.redhat.com/security/cve/cve-2018-10195

This means that the CVE doesn&apos;t appear in triage, and can&apos;t be searched.  It&apos;s like a ghost CVE that you&apos;ll never know about.

Could srtool know that CVEs are incrementing and if there are any gaps in the data then put them in triage so the user can see if its still reserved (and leave it pending), or discover that e.g. Red Hat has more data and triage appropriately.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>82528</commentid>
    <comment_count>1</comment_count>
    <who name="David Reyna">david.reyna</who>
    <bug_when>2018-12-18 05:32:33 +0000</bug_when>
    <thetext>In the latest update:

1. After the NIST CVEs are scanned, the MITRE database is scanned for any CVEs that have not been created from the NIST data.

This data is the missing &quot;reserved&quot; CVEs.

2. When the &quot;New&quot; CVEs are scanned and scored, the CVE data from the alternate CVE sources are automatically registered (except for sources that are without bulk downloads and are REST accessed only).

This provides the comparison CVE sources automatically for the triage process.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>82764</commentid>
    <comment_count>2</comment_count>
    <who name="David Reyna">david.reyna</who>
    <bug_when>2019-01-12 18:30:33 +0000</bug_when>
    <thetext>Implemented</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>