January 17, 2008

Red Hat and Firefox more buggy than Microsoft

Secunia reports the number of security bugs in the Red Hat Linux OS and Firefox browsers outstripped comparable products from Microsoft

Secunia has found that the number of security bugs in the open source Red Hat Linux operating system and Firefox browsers far outstripped comparable products from Microsoft last year.

In a report released this week, Secunia also criticized CA for the quality of the code in its anti-virus products, saying that "inherent" code problems are exposing CA products to ongoing security vulnerabilities.

On the other hand, "zero-day" security bugs in Firefox were patched more quickly than in Microsoft Internet Explorer, according to the Secunia 2007 Report, released this week.

In a review of the number of vulnerabilities found in enterprise anti-virus vendors' products, Secunia found that CA was by far the leader, with 187 vulnerabilities, followed by Symantec with 73. Trend Micro (34), ClamAV (15), McAfee (13) and F-Secure (6) ranked lower on the list.

The high figures for Symantec and CA are partly due to their wide range of products, some of which cover areas other than anti-virus, Secunia said.

However, the majority of the CA bugs were due to "inherent code problems with some CA products", Secunia said in the report.

Of particular concern is CA's range of ARCServe Backup products for laptops and desktops, which Secunia submitted to its Binary Analysis process after several bugs were reported and fixed. The bugs involved errors in processing particular arguments and requests.

The analysis found that about 60 reported bugs were still present in the supposedly patched versions.

What's more, the analysis found that the vulnerabilities were partly due to "the nature of the product code itself", Secunia said.

"Unless an overhaul of the code is undertaken, then the product remains susceptible to similar types of vulnerabilities," Secunia said.

However CA said in a statement that it has rigorous quality-control measures in place for its software and continues to improve those measures.

A number of the vulnerabilities found in Symantec products were due to their use of vulnerable software from third-party developers, Secunia said.

One of these is the Autonomy Keyview SDK (software development kit), used in Symantec Mail to view Lotus 1-2-3 files. The component was reported to have a "highly critical" flaw on 12 December, but hasn't yet been patched, leaving some Symantec products vulnerable.

Symantec said in a statement that it has published instructions for mitigating the problem and has issued product updates for some affected vendors. IBM, whose Lotus Notes was also affected by the Autonomy bug, has issued its own patch.

Operating systems and browsers

Out of the operating systems monitored by Secunia -- Windows (98 and onwards), Mac OS X, HP-UX 10.x and 11.x, Solaris 8, 9, and 10 and Red Hat (excluding Fedora) -- Red Hat was found to have by far the most vulnerabilities, at 633, with 99 percent found in third-party components. (Linux distributions are generally composed mostly of third-party software, which is integrated by the distributor.)

Red Hat has taken issue with the figures, claiming the accurate number should be 404 vulnerabilities for last year.

Solaris came next, with 252 bugs, 80 percent of which were in third-party components. Mac OS X came after that with 235, 62 percent of which were third-party.

Close

On Twitter now

Platforms

Powered by Twitter

On Twitter now

additional resources
White Paper - How to Improve Delivery of Advanced Web Applications

White Paper

Virtual Workforce: The Key to Expanding The Business While Cutting Costs

Get the independent advice and expertise you need to support a virtual workforce.

Go inside:
The three-step approach to making a virtual workforce a reality.
The four flavors of client virtualization technologies.
The three key initiatives that solve IT challenges.
Download now »
White Paper: Successfully Secure Your Wireless LAN With Wi-Fi firewalls.

White Paper

Addressing Linux Threats Leveraging Fewer Resources

The increase in Linux popularity has increased the frequency and sophistication of malware attacks. Read this 2 page white paper now to learn how you can protect your Linux environment with real-time protection that is certified by all major Linux vendors.

Download now »
White Paper - The 2009 Handbook of Application Delivery

White Paper

The 2009 Handbook of Application Delivery

Ensuring acceptable application delivery will become even more difficult over the next few years. As a result, IT organizations need to ensure that the approach that they take to resolving the current application delivery challenges can scale to support the emerging challenges. This handbook elaborates on the key tasks associated with planning, optimization, management and control and provides decision criteria to help IT organizations choose appropriate solutions.

Download now »
White Paper - Is Your Backup System Outdated?

White Paper

Mid-range Storage Considerations

A common misconception is that mid-range storage requirements are dramatically different than that of a larger enterprise. Mid-range storage users may require less capacity, but they have similar functionality and management requirements. This ESG paper examines mid-range storage needs and reviews a new solution that adjusts size while retaining value, performance and functionality.

Download now »

Sign up to receive Platforms Resource Alerts

Subscribe to the Today's Headlines: First Look Newsletter

Find out what will be news for the day, with our first-thing-in-the-morning briefing.

©1994-2010 Infoworld, Inc.