<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Cloud &#38; Telecom Security &#187; CVE</title>
	<atom:link href="http://sbin.cn/blog/tag/cve/feed/" rel="self" type="application/rss+xml" />
	<link>http://sbin.cn/blog</link>
	<description>Technologies and comments on cloud and telecom security, bridging China and the world!</description>
	<lastBuildDate>Thu, 02 Feb 2012 08:30:24 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
		<item>
		<title>软件厂商须承担更多安全责任 &#8211; 从丰田汽车召回事件说起</title>
		<link>http://sbin.cn/blog/2010/02/23/more-responsibility-by-software-vendors/</link>
		<comments>http://sbin.cn/blog/2010/02/23/more-responsibility-by-software-vendors/#comments</comments>
		<pubDate>Tue, 23 Feb 2010 19:49:31 +0000</pubDate>
		<dc:creator>Richard</dc:creator>
				<category><![CDATA[-Chinese-]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[CVE]]></category>
		<category><![CDATA[网络安全]]></category>
		<category><![CDATA[SANS]]></category>
		<category><![CDATA[SDLC]]></category>
		<category><![CDATA[云计算]]></category>

		<guid isPermaLink="false">http://sbin.cn/blog/?p=1619</guid>
		<description><![CDATA[想必大家都关注到了这次获得媒体广泛关照的丰田汽车召回事件，Google上面搜索“丰田汽车召回”，刚刚的搜索结果数是8.8M+。虽然说    汽车家电等召回事件在中国国内，拜国内消费者“保护”所赐，不是很多，消费者大都哑巴吃黄连了。可是，这在西方发达国家是惯例 &#8211; 你生产的产品出了质量问题，召回-免费修补是天经地义的事情。 回过来在看看我们所处的IT和软件业呢？大家随便找到一份商业软件的license agreement等，逼着你签过字的那种，都明明白白写着 &#8211; 本软件“as-is”；不保证不出漏洞；出了漏洞不保证什么时候可以出补丁；出了补丁，不保证那个补丁管用；软件使用中出了事故，赔偿金额不会超过软件价格；&#8230;. 在IT和软件作为新兴行业时，对这种高风险的新生事物特例一些保护是可以理解的。但是，当这个行业里占据了越来越多的500强、产生了越来越多的亿万富翁时，对此基本市场义务的反思就成为很容易理解的动向了。 SANS和Mitre Corp，这两个大名鼎鼎的组织联袂发起了这个很有思想性的项目。说其“很有思想性”，是因为我想这个问题也有不少时间了。为软件和安全厂商工作，这种感觉不会有，或不会很明显。但是作为内部IT运行人员就不一样了。你的病毒系统误杀了几千台电脑的软件，搞当了数百个服务器，我居然无法通过合同/许可条款获得正常的赔偿？很让人窝火。你的软件出了漏洞，厂商不但迟迟不响应补丁，还似乎成了用户的责任 &#8211; 当初签字画押时就说好的 as-is&#8230; 虽然说大浪淘沙，让客户不满意的厂商最终会被市场淘汰，但是，这个规则用到“安全”上时，就不是很灵，或太“慢”了。 SANS和Mitre Corp号召大家改一下合同的模板，把规矩重新定一定！ Alan Paller, director of research with the institute, said that nearly every attack is enabled by programming mistakes that provide a handhold for attackers. &#8220;The only way programming errors can be eradicated is by making software development organisations [...]]]></description>
		<wfw:commentRss>http://sbin.cn/blog/2010/02/23/more-responsibility-by-software-vendors/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>China National Vulnerability Database gets online</title>
		<link>http://sbin.cn/blog/2009/10/19/china-national-vulnerability-database-gets-online/</link>
		<comments>http://sbin.cn/blog/2009/10/19/china-national-vulnerability-database-gets-online/#comments</comments>
		<pubDate>Mon, 19 Oct 2009 14:39:05 +0000</pubDate>
		<dc:creator>Richard</dc:creator>
				<category><![CDATA[-English-]]></category>
		<category><![CDATA[Architect]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Telecom]]></category>
		<category><![CDATA[CERT]]></category>
		<category><![CDATA[CNVD]]></category>
		<category><![CDATA[CNVDB]]></category>
		<category><![CDATA[CVE]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[NVD]]></category>
		<category><![CDATA[SVM]]></category>

		<guid isPermaLink="false">http://sbin.cn/blog/?p=1440</guid>
		<description><![CDATA[Oct.18 2009(Beijing time), China CCTV news reported the release of national vulnerability database of China. Along with the upsoaring of the Internet applications, the vulnerability number is also in a sharp growth. So the update and automation of vulnerability information is becoming more and more critical for the whole information ssytems. Vulnerability Database is used [...]]]></description>
		<wfw:commentRss>http://sbin.cn/blog/2009/10/19/china-national-vulnerability-database-gets-online/feed/</wfw:commentRss>
		<slash:comments>26</slash:comments>
		</item>
		<item>
		<title>Adope再爆新漏洞,补丁要下周才出</title>
		<link>http://sbin.cn/blog/2009/10/09/adope-vulnerability/</link>
		<comments>http://sbin.cn/blog/2009/10/09/adope-vulnerability/#comments</comments>
		<pubDate>Fri, 09 Oct 2009 15:51:44 +0000</pubDate>
		<dc:creator>Richard</dc:creator>
				<category><![CDATA[-Chinese-]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Adope]]></category>
		<category><![CDATA[CVE]]></category>
		<category><![CDATA[漏洞]]></category>

		<guid isPermaLink="false">http://sbin.cn/blog/?p=1423</guid>
		<description><![CDATA[Adope官方已经确认再爆新漏洞。该漏洞存在于Windows, Macintosh, Unix版本的Adobe Reader和Acrobat 9.1.3和以前的版本（CVE-2009-3459），有报告称已经发现针对Windows版本的利用。漏洞细节详见下文报道： Adobe is aware of reports of a critical vulnerability in Adobe Reader and Acrobat 9.1.3 and earlier (CVE-2009-3459) on Windows, Macintosh and UNIX. There are reports that this issue is being exploited in the wild in limited targeted attacks; the exploit targets Adobe Reader and Acrobat 9.1.3 on Windows. Adobe [...]]]></description>
		<wfw:commentRss>http://sbin.cn/blog/2009/10/09/adope-vulnerability/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>[Chinese]NIST推出通用配置打分系统CCSS草案</title>
		<link>http://sbin.cn/blog/2008/06/09/nist-ccss/</link>
		<comments>http://sbin.cn/blog/2008/06/09/nist-ccss/#comments</comments>
		<pubDate>Mon, 09 Jun 2008 13:33:51 +0000</pubDate>
		<dc:creator>Richard</dc:creator>
				<category><![CDATA[-Chinese-]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[CCSS]]></category>
		<category><![CDATA[CVE]]></category>
		<category><![CDATA[CVSS]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[NIST]]></category>

		<guid isPermaLink="false">http://sbin.cn/blog/?p=395</guid>
		<description><![CDATA[5月30日，NIST（美国技术标准局）推出了一个用于对安全配置进行打分的草案，其全称是：NIST IR-7502 DRAFT The Common Configuration Scoring System (CCSS) 。 CCSS是用于对有关软件安全配置问题（Issue）的特征和影响提供的一个标准测量集合。CCSS可以帮助企业组织在解决安全问题时做出正确的决定，另外，它还可以提供数据以便对主机的安全状况进行量化的评估。从体系上看，CCSS借鉴了CVSS，但是针对软件的安全配置问题做了特别调整（CVSS专注于软件缺陷和漏洞）。我们知道，一个软件系统的安全性，不仅仅是软件本身的安全问题，很大程度上还决定于安装、配置和运行管理。 据报道，NIST还计划扩展CCSS，将环境度量也包含进来。点击下载原文。]]></description>
		<wfw:commentRss>http://sbin.cn/blog/2008/06/09/nist-ccss/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>“Common Weakness Enumeration” Added to CVE Web Site</title>
		<link>http://sbin.cn/blog/2006/03/16/common-weakness-enumeration-added-to-cve-web-site/</link>
		<comments>http://sbin.cn/blog/2006/03/16/common-weakness-enumeration-added-to-cve-web-site/#comments</comments>
		<pubDate>Thu, 16 Mar 2006 09:40:59 +0000</pubDate>
		<dc:creator>Richard</dc:creator>
				<category><![CDATA[-English-]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[CVE]]></category>

		<guid isPermaLink="false">http://sbin.cn/blog/?p=207</guid>
		<description><![CDATA[March 15, 2006, according to the official news from mitre.org, a new effort leveraging CVE entitled the &#8220;Common Weakness Enumeration (CWE)&#8221; has been added to the GET CVE page on the CVE Web site. CWE is a community-developed formal list of common software weaknesses, idiosyncrasies, faults, and flaws. The intention of CWE is to serve [...]]]></description>
		<wfw:commentRss>http://sbin.cn/blog/2006/03/16/common-weakness-enumeration-added-to-cve-web-site/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
	</channel>
</rss>

