Re: [users@httpd] CVE NIST discrepancies

2020-08-14 Thread Eric Covener
On Fri, Aug 14, 2020 at 4:06 PM Nic P wrote: > > Thanks Eric - there are unfortunately a long list of similar CVE's > so this has created an audit nightmare > > 1999-0070 > 1999-0236 > 1999-0289 > 2001-0131 > 2001-1556 > 2007-0086 > 2007-1349 > 2007-4723 > 2007-5156 > 2008-2579 > 2009-0796 > 2009

Re: [users@httpd] CVE NIST discrepancies

2020-08-14 Thread Nic P
Thanks Eric - there are unfortunately a long list of similar CVE's so this has created an audit nightmare 1999-0070 1999-0236 1999-0289 2001-0131 2001-1556 2007-0086 2007-1349 2007-4723 2007-5156 2008-2579 2009-0796 2009-2299 2011-1176 2011-1752 2011-1783 2011-2688 2012-3526 2012-4001 2012-4360 2

Re: [users@httpd] CVE NIST discrepancies

2020-08-14 Thread Eric Covener
On Fri, Aug 14, 2020 at 11:49 AM Nic P wrote: > > Hi > > I am struggling through an audit with explaining CVE's listed on NIST that do > not appear on the Apache site with any fixes. > > CVE-1999-0070 is an example showing in nist site as impacting Apache, but no > reference to this on the Apach

[users@httpd] CVE NIST discrepancies

2020-08-14 Thread Nic P
Hi I am struggling through an audit with explaining CVE's listed on NIST that do not appear on the Apache site with any fixes. CVE-1999-0070 is an example showing in nist site as impacting Apache, but no reference to this on the Apache security pages https://nvd.nist.gov/vuln/detail/CVE-1999-007