SoylentNews
SoylentNews is people
https://soylentnews.org/

Title    CVE 10K is Almost Here
Date    Friday September 19 2014, @10:47PM
Author    LaminatorX
Topic   
from the ought-to-be-enough-for-anybody dept.
https://soylentnews.org/article.pl?sid=14/09/19/2057251

Leebert writes:

Common Vulnerabilities and Exposures (CVE) is a standard identifier for referencing known security vulnerabilities in the information security world. The identifiers are broadly used in security products such as vulnerability scanners, providing a convenient way of cross-referencing data between various tools and databases. For most of its existence, the CVE Identifier for any given vulnerability has been in the format CVE-YYYY-NNNN, where YYYY is the year the identifier was assigned, and NNNN is an incrementing fixed-width number that restarts every year.

Because the time is fast approaching where there will be more than 10,000 CVE Identifiers assigned in a year, the CVE Identifier syntax has been updated to support variable-length numbers which is likely to pose a problem for applications which have not been updated to permit more than 4 digits in the identifier. The change was adopted in July of last year, taking effect on January 1, 2014.

Personally, it sometimes feels to me that CVE identifiers are being wasted on silly things like esoteric mobile apps, but I concede that running out of numbers is an inevitability regardless of the editorial stance of the CVE Editorial Board.

Links

  1. "Leebert" - https://soylentnews.org/~Leebert/
  2. "CVE Identifier syntax has been updated to support variable-length numbers" - https://cve.mitre.org/cve/identifiers/syntaxchange.html
  3. "adopted in July of last year" - https://cve.mitre.org/news/archives/2013_news.html#jul172013a
  4. "esoteric mobile apps" - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5957

© Copyright 2024 - SoylentNews, All Rights Reserved

printed from SoylentNews, CVE 10K is Almost Here on 2024-04-25 19:27:32