kavat
kavat

Reputation: 21

How to get CPE from package?

I have a question related to CPE. Does it exist a method that ensure full translation among package installed and its CPE? Example: package for apache2, in Ubuntu or RedHat, is named apache2 or httpd but its CPE is similar to :apache:http_server: (apache is the vendor and http_server the product name) and obviously if I search for CPE like ::apache2: or ::httpd: I cannot found nothing. Can you help me please?

Upvotes: 2

Views: 1565

Answers (1)

Jonas Stein
Jonas Stein

Reputation: 7043

You can look up the registered products in the CPE database on https://nvd.nist.gov/products/cpe

Some distributions add CPE information also in the packages, so you can use the package manager to look it up. Gentoo Linux for instance provides a cpe field in the metadata.xml file.

Additionally you can look up the CPE data in repology which is not authoritative.

Upvotes: 0

Related Questions