Red Hat and Firefox more buggy than Microsoft

Windows not that bad after all.

Secunia has found that the number of security bugs in the open source Red Hat Linux operating system and Firefox browsers far outstripped comparable products from Microsoft last year.

In a report released this week, Secunia also criticised CA for the quality of the code in its anti-virus products, saying that "inherent" code problems are exposing CA products to ongoing security vulnerabilities.

On the other hand, "zero-day" security bugs in Firefox were patched more quickly than in Microsoft Internet Explorer, according to the Secunia 2007 Report, released this week.

In a review of the number of vulnerabilities found in enterprise anti-virus vendors' products, Secunia found that CA was by far the leader, with 187 vulnerabilities, followed by Symantec with 73. Trend Micro (34), ClamAV (15), McAfee (13) and F-Secure (6) ranked lower on the list.

The high figures for Symantec and CA are partly due to their wide range of products, some of which cover areas other than anti-virus, Secunia said.

However, the majority of the CA bugs were due to "inherent code problems with some CA products", Secunia said in the report.

Of particular concern is CA's range of ARCServe Backup products for laptops and desktops, which Secunia submitted to its Binary Analysis process after several bugs were reported and fixed. The bugs involved errors in processing particular arguments and requests.

The analysis found that about 60 reported bugs were still present in the supposedly patched versions.

What's more, the analysis found that the vulnerabilities were partly due to "the nature of the product code itself", Secunia said.

"Unless an overhaul of the code is undertaken, then the product remains susceptible to similar types of vulnerabilities," Secunia said.

However CA said in a statement that it has rigorous quality-control measures in place for its software and continues to improve those measures.

A number of the vulnerabilities found in Symantec products were due to their use of vulnerable software from third-party developers, Secunia said.

One of these is the Autonomy Keyview SDK (software development kit), used in Symantec Mail to view Lotus 1-2-3 files. The component was reported to have a "highly critical" flaw on 12 December, but hasn't yet been patched, leaving some Symantec products vulnerable.

Symantec said in a statement that it has published instructions for mitigating the problem and has issued product updates for some affected vendors. IBM, whose Lotus Notes was also affected by the Autonomy bug, has issued its own patch.

Operating systems and browsers
Out of the operating systems monitored by Secunia - Windows (98 and onwards), Mac OS X, HP-UX 10.x and 11.x, Solaris 8, 9, and 10 and Red Hat (excluding Fedora) - Red Hat was found to have by far the most vulnerabilities, at 633, with 99 percent found in third-party components. (Linux distributions are generally composed mostly of third-party software, which is integrated by the distributor.)

Red Hat has taken issue with the figures, claiming the accurate number should be 404 vulnerabilities for last year.

Solaris came next, with 252 bugs, 80 percent of which were in third-party components. Mac OS X came after that with 235, 62 percent of which were third-party.

Windows had only 123 bugs reported, but 96 percent of those were found in the operating system itself. HP-UX had 75 bugs reported, 81 percent of which were in third-party code.

Last week, a US Department of Homeland Security (DHS) bug-fixing scheme uncovered an average of one security glitch per 1,000 lines of code in 180 widely used open source software projects.

The large number of Red Hat flaws is partly due to the large number and wide variety of components it includes.

"Red Hat contains two different browsers and graphic interfaces, a number of PDF readers and image editors, and so on," the report said. "Red Hat, HP-UX, and Solaris can easily be used as servers, and as such include and support a large number of third party components, while the same cannot be said of all versions of Windows and Mac OS X."

Any consideration of relative OS security should look at factors not covered by the report, such as average patching time for vulnerabilities, Secunia said.

In the browser field, Firefox led the way with 64 bugs, compared to 43 for Internet Explorer, and 14 each for Opera and Safari.

However, in an examination of zero-day flaws - reported by third parties before a patch was available - Secunia found that Firefox tended to get more patches, sooner, compared to IE.

Out of eight zero-day bugs reported for Firefox in 2007, five have been patched, three of those in just over a week. Out of 10 zero-day IE bugs, only three were patched and the shortest patch time was 85 days.

ActiveX was hit by the largest number of browser add-on bugs in 2007, with 339 (compared to 45 last year), Secunia said.

The figure was propped up by the Month of ActiveX Controls Bugs in May 2007, and by Secunia's discovery of a vulnerable ActiveX component that was used in 40 different products.

Quicktime followed with 35 bugs and Java with 21 bugs.


What are your views on this subject? Use the form below to post a comment on this article up to 500 characters.


Characters remaining: 500

Add your commentComments

Ron | Published: 15:48 GMT, 20 January 2008

So how much did Microsoft pay you?

James | Published: 05:21 GMT, 19 January 2008

"""In the browser field, Firefox led the way with 64 bugs, compared to 43 for Internet Explorer, and 14 each for Opera and Safari. However, in an examination of zero-day flaws - reported by third parties before a patch was available - Secunia found that Firefox tended to get more patches, sooner, compared to IE. Out of eight zero-day bugs reported for Firefox in 2007, five have been patched, three of those in just over a week. Out of 10 zero-day IE bugs, only three were patched and the shortest patch time was 85 days.""" Secunia tends to list only some of the Opera vulnerabilities and usually only after they were fixed so the 14 is not a realistic claim. So Firefox is more buggy or vulnerable simply because Mozilla is much more open about this than the others and being open source? blog.mozilla.com/security/2008/01/17/read-past-the-headlines-firefox-is-fixed-faster/

Techworld Editor | Published: 15:18 GMT, 18 January 2008

We don't normally comment on readers' comments but I' would like to pick up on what Roy says about our report not being balanced. We do point out that Red Hat flaws are fixed quicker and also point out that the number of Red Hat flaws are due, in part, to the number of components that it supports: in effect, what ZD Net says.

Roy Schestowitz | Published: 07:44 GMT, 18 January 2008

Proper balance in this article seems to be missing. Here's what ZDNet said: "Secunia said that while Red Hat had more reported vulnerabilities than Windows, it was not possible to compare its relative security with Microsoft products, or comment on the relative security of open-source versus proprietary products based on vulnerability figures. "It's impossible to make a fair comparison ?;; it's like comparing apples to oranges," Thomas Kristensen, Secunia's chief technology officer, told ZDNet.co.uk. "Red Hat has the highest number of applications included, so the number of vulnerabilities that affect it is bound to be higher."

Matt Cahill | Published: 15:14 GMT, 17 January 2008

I'm glad they attempted to qualify the findings by mentioning that RH comes with (immensely) more 3rd-party applications than any Microsoft OS - while this does proportionately increase the likelihood of bugs overall, it's important to understand that by sheer bug-count alone, one cannot perform an apple-to-apple comparison between the two for this reason.

Bradley Holt | Published: 14:50 GMT, 17 January 2008

Most likely the number of bugs found in open source software is greater because the source can be examined. The key here is the number of bugs found. Who knows how many bugs actually exist since it's harder for security experts to find the bugs in closed source software. The article can be misleading.

Andy Macdonald | Published: 14:07 GMT, 17 January 2008

CA were well known in the 80s & 90s for acquiring software companies and then allegedly continuing to squeeze money out of the products while cutting back on R&D, etc. I don't know if they have changed.

Related Security news

Hacker attacks on US military jump sharply in 2009

China source of most attacks, says report

Microsoft denies building security 'backdoor' in Windows 7

Privacy organisations shouldn't read too much into NSA involvement it says

Pentagon expands exclusive deal with McAfee

Department of Defense uses McAfee products

Police arrest pair over global banking web scam

Man and woman arrested in Manchester for using notorious Zeus Trojan



Email this article to a friend or colleague:


PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

Database security: Preventing enterprise data leaks at the source

IDC discusses the growing internal threats to business information, the impact of government regulations on the protection of data, and how enterprises must adopt database security best practices...

Download Whitepaper

Service-oriented security

SOA has become an integral part of enterprise software by providing a framework to efficiently develop software as services that is easily sharable, reusable, and integrated. No where is the need more apparent than in the Identity Management space. Welcome to the age of Service-Oriented Security (SOS).

Download Whitepaper

Data protection prospective vendor checklist

Organisations need a way to map business needs against all these challenges in procuring a technical solution. To help, SANS has developed the following Prospective Vendor Checklist.

Download Whitepaper

Unlock the power of the mainframe

This whitepaper presents the notion of CICS as an integration hub based on a component-based, service-oriented architecture supporting Web services. Highlights will review the challenges and contrasted support for Web services natively in CICS.

Download Whitepaper

Techworld UK - Technology - Business

COLT White Paper

Are all VoIP services the same?

Questions to ask your service provider to ensure you get the VoIP service you need
With careful choice of partner, your business can have all the advantages of VoIP access - reduced costs, flexibility and simplicity - without the drawbacks.
This white paper is your guide to ensure you get right the VoIP service and details the pitfalls which businesses would do well to avoid.

Download white paper
BMC

Ride the express lane in the journey to speed ITIL adoption

Explore the challenges in making the journey to ITIL and the criteria for selecting consulting services
By following ITIL practices, your IT organisation will become more closely integrated with the business. We recommend making the journey to ITIL in a sequence of six incremental steps, the phases of which are driven through execution of a strategic transformational roadmap.

Download white paper

Webcast: IT Financial Management: Cost Optimisation for Efficiency and Agility.
On Demand Webcast
Join this webcast to learn about the techniques and technologies that can help you prove the value of IT to the business by understanding the true cost of today's IT services and those that will be necessary to deliver future success.

Register Today

Site Map

IDG Network

* *