Reputation: 21
I have a question related to CPE. Does it exist a method that ensure full translation among package installed and its CPE? Example: package for apache2, in Ubuntu or RedHat, is named apache2 or httpd but its CPE is similar to :apache:http_server: (apache is the vendor and http_server the product name) and obviously if I search for CPE like ::apache2: or ::httpd: I cannot found nothing. Can you help me please?
Upvotes: 2
Views: 1565
Reputation: 7043
You can look up the registered products in the CPE database on https://nvd.nist.gov/products/cpe
Some distributions add CPE information also in the packages, so you can use the package manager to look it up.
Gentoo Linux for instance provides a cpe
field in the metadata.xml file.
Additionally you can look up the CPE data in repology which is not authoritative.
Upvotes: 0