Skip Links

Network World

  • Social Web 
  • Email 
  • Close

Red Hat and Firefox more buggy than Microsoft

By Matthew Broersma , TechWorld , 01/17/2008
Newsletter Signup
  • Share/Email
  • Tweet This
  • Comment
  • Print

Secunia has found that the number of security bugs in the open source Red Hat Linux operating system and Firefox browsers far outstripped comparable products from Microsoft last year.

In a report released this week, Secunia also criticized CA for the quality of the code in its antivirus products, saying that "inherent" code problems are exposing CA products to ongoing security vulnerabilities.

On the other hand, "zero-day" security bugs in Firefox were patched more quickly than in Microsoft Internet Explorer, according to the Secunia 2007 Report, released this week.

In a review of the number of vulnerabilities found in enterprise anti-virus vendors' products, Secunia found that CA was by far the leader, with 187 vulnerabilities, followed by Symantec with 73. Trend Micro (34), ClamAV (15), McAfee (13) and F-Secure (6) ranked lower on the list.

The high figures for Symantec and CA are partly due to their wide range of products, some of which cover areas other than anti-virus, Secunia said.

However, the majority of the CA bugs were due to "inherent code problems with some CA products," Secunia said in the report.

Of particular concern is CA's range of ARCServe Backup products for laptops and desktops, which Secunia submitted to its Binary Analysis process after several bugs were reported and fixed. The bugs involved errors in processing particular arguments and requests.

The analysis found that about 60 reported bugs were still present in the supposedly patched versions.

What's more, the analysis found that the vulnerabilities were partly due to "the nature of the product code itself", Secunia said.

"Unless an overhaul of the code is undertaken, then the product remains susceptible to similar types of vulnerabilities," Secunia said.

However CA said in a statement that it has rigorous quality-control measures in place for its software and continues to improve those measures.

A number of the vulnerabilities found in Symantec products were due to their use of vulnerable software from third-party developers, Secunia said.

One of these is the Autonomy Keyview SDK (software development kit), used in Symantec Mail to view Lotus 1-2-3 files. The component was reported to have a "highly critical" flaw on 12 December, but hasn't yet been patched, leaving some Symantec products vulnerable.

  • Share/Email
  • Tweet This
  • Comment
  • Print
Comments (4)
Login
Forgot your account info?

RE: Bad headline, OK articleBy Anonymous on January 22, 2008, 12:25 pmI couldn't agree more. When I read the article heading, my first thought was "Did MS fund this review?" In a degree of fairness to MS, it is a bit hard to compare...

Reply | Read entire comment

article title misleading...By Anonymous on January 18, 2008, 12:25 pm"Out of eight zero-day bugs reported for Firefox in 2007, five have been patched, three of those in just over a week. Out of 10 zero-day IE bugs, only three were...

Reply | Read entire comment

Bad headline, OK articleBy Anonymous on January 18, 2008, 12:07 pmThe headline shows a fundamental misunderstanding of what Linux is and can do. Saying Red Hat is more buggy because of the packages that can be installed (and...

Reply | Read entire comment

RE: Red Hat and Firefox more buggy than MicrosoftBy jheary on January 18, 2008, 11:51 amGreat Article. Very useful information.

Reply | Read entire comment

View all comments

Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed