Secunia: More Red Hat flaws than Microsoft in 2007

NEWS

Danish vulnerability research company Secunia has said there were more flaws reported for Red Hat operating systems than for Microsoft operating systems in 2007.

In a paper entitled Secunia 2007 Report that was made available to Secunia customers on Monday, the company compared last year's vulnerability reports for five operating systems: Microsoft Windows (98 and onwards); Mac OS X; HP-UX 10.x and 11.x; Solaris 8, 9, and 10; and Red Hat (excluding Fedora).

The company found that Red Hat had the most reported vulnerabilities out of those operating systems, with 633 flaws. Solaris had a total of 252 vulnerabilities, while Apple Mac OS X came third with 235. Windows came fourth with 123, while HP-UX had 75 reported flaws.

However, Red Hat Security Team director Mark Cox denied that the vulnerability count was as high as 633 for Red Hat, instead claiming 404 vulnerabilities in 2007.

"Secunia released a security summary report for 2007 and surprisingly gave a count for Red Hat for the year at over 600 vulnerabilities," said Cox. "I've no idea how they got to this number, it certainly doesn't match our metrics. For every Red Hat product and service for 2007 we issued 306 advisories to fix 404 vulnerabilities. Of those 404 vulnerabilities 41 were critical."

Most people would not be using every Red Hat product, said Cox. Taking just Red Hat's Enterprise Linux product, there were 48 vulnerabilities, of which 27 were critical, Cox said.

Cox added that a raw count of vulnerabilities "isn't much use and is only a small part of the overall risk exposure in using a product".

Secunia said that while Red Hat had more reported vulnerabilities than Windows, it was not possible to compare its relative security with Microsoft products, or comment on the relative security of open-source versus proprietary products based on vulnerability figures.

"It's impossible to make a fair comparison — it's like comparing apples to oranges," Thomas Kristensen, Secunia's chief technology officer, told ZDNet.co.uk. "Red Hat has the highest number of applications included, so the number of vulnerabilities that affect it is bound to be higher."

Red Hat contains two different browsers and graphic interfaces, as well as a number of PDF readers and image editors, said Secunia. Red Hat, HP-UX and Solaris can be used as servers, so include and support a large number of third-party components, while "the same cannot be said of all versions of Windows and Mac OS X", Secunia explained.

"Web servers, database servers, archiving tools, office productivity suites — there's two of everything when it comes to Red Hat," said Kristensen. "Windows XP can only be used as a workstation. If you want to run XP as, say, a web server, you have to buy either Microsoft or third-party software."

Kristensen said that third-party software was a key factor affecting the number of vulnerabilities attributed to the respective operating systems. With Red Hat, 99 percent, or 629 of the vulnerabilities, were due to third-party components. With Windows, four percent of flaws were due to third-party software.

One of the differences between the operating systems, said Kristensen, was that Red Hat notified customers of third-party flaws that affected its operating systems, as well as supporting them. Microsoft, on the other hand, only notified customers of flaws within its control.

"If you don't have to install third-party tools on Red Hat systems, it's easier to know about vulnerabilities," said Kristensen. "With Microsoft, you have to get Microsoft bulletins, Apple bulletins, Adobe bulletins — wherever you got the software from." Kristensen added that the time taken to patch critical, publicly disclosed vulnerabilities was also much longer for Microsoft systems, compared with open-source software.

"The general trend is that critical issues in open-source applications have a much shorter patch time compared with Microsoft," said Kristensen. "For irresponsibly disclosed flaws, patching time is critical. Microsoft is a very big company with a certain level of bureaucracy — only Microsoft can fix patching errors. There's a quality assurance testing period before a patch is available. With open source, if there's an incompatibility with a patch, you can change the code. There's an open dialogue with a community, and you can fix it from there."

Talkback

The same Apache vulnerability was counted 6 times. Secunia treats the same advisory that affectsRed Hat Enterprise Linux 2.1, 3, 4, 5, Red Hat Application Stack v1, v2 as 6 different ones.

Mark Cox, Redhat's Security lead says, "
Using our public tool, for every Red Hat product and service, for 2007
we issued 306 advisories to fix 404 vulnerabilities. Of those 404
vulnerabilities 41 were critical (on the scale used by Microsoft and
Red Hat)."
Source: http://www.awe.com/mark/blog/200801161200.html

ZDNET Editors, please update this article with that blog posting. It brings things into perspective.

SEJeff 16 Jan 08 15:40 Reply

Thank you for taking the time to reply to this story, SEJeff, especially as if you're in Hollywood it must be the middle of the night about now!

Thanks also for pointing out Mark Cox's blog post. Red Hat made me aware of his post and those stats, which is why the stats are already in the story, in the fifth paragraph.

Cheers,

Tom

Tom Espiner 16 Jan 08 16:05 Reply

I'm sorry, but where in the article does it make clear that the Secunia figures include counting aberrations for the Red Hat figures such as the "same Apache vulnerability was counted 6 times."?

I cannot find it and I have read the article a couple of times.

interoperate 17 Jan 08 03:10 Reply

Please read the blog posting referenced in my comment. Text from that blog is referenced in this article

SEJeff 17 Jan 08 03:16 Reply

Post your comment

In order to post a comment you need to be registered and logged in

Log in or create your ZDNet UK account below

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Membership FAQ

ZDNet UK Live

dava4444

this spam bot is exasperating

4 hours ago by dava4444 on I'd Rather Have a Bigger Byte Than a Little bit...Broadband
dava4444

:D I think the server exchange does slow down a bit round 5 to 7/8 pm but I find I mostly get 3 to 4 MBps on downloads and by that time there...

4 hours ago by dava4444 on I'd Rather Have a Bigger Byte Than a Little bit...Broadband
dava4444

night before last

4 hours ago by dava4444 on I'd Rather Have a Bigger Byte Than a Little bit...Broadband
dava4444

5MBps, I saw 5.8

4 hours ago by dava4444 on I'd Rather Have a Bigger Byte Than a Little bit...Broadband
dava4444

honestly I do get

4 hours ago by dava4444 on I'd Rather Have a Bigger Byte Than a Little bit...Broadband
dava4444

thank you for the support. ..but in

4 hours ago by dava4444 on I'd Rather Have a Bigger Byte Than a Little bit...Broadband
dava4444

if you download a BIG file from the MS site then THAT is your *true* speed.

4 hours ago by dava4444 on I'd Rather Have a Bigger Byte Than a Little bit...Broadband
dava4444

Hi Fat Pop Do Wop!

4 hours ago by dava4444 on I'd Rather Have a Bigger Byte Than a Little bit...Broadband
dava4444

it filters the word 'aittude' mis spelled intentionally

4 hours ago by dava4444 on How to build a GUI for a toaster
dava4444

but with a fair amount of work, possibly. God Bless Dava

4 hours ago by dava4444 on How to build a GUI for a toaster
dava4444

But I think Googles idea could be developed into an able paradigm. right now, no.

4 hours ago by dava4444 on How to build a GUI for a toaster
dava4444

took there repos down for Ubuntu (I think there back now but they took a few months). I don't think there is a perfect answer,

7 hours ago by dava4444 on How to build a GUI for a toaster
dava4444

but the community coding and ideas would be gratis, maybe that's why OEM's can be 'slackers' when it comes to Linux. they just sit back and let...

7 hours ago by dava4444 on How to build a GUI for a toaster
dava4444

continued the bad point about that is hardware, a rival OEM can take your development and use it themselves and to retaliate you would have to go...

7 hours ago by dava4444 on How to build a GUI for a toaster
dava4444

continued Okay how about something like Google's approach 'semi-open source'? . the OEM pours cash in to development and code, whilst opening it...

7 hours ago by dava4444 on How to build a GUI for a toaster
dava4444

Hi Adrian em, interesting, yeah okay I can get this vibe, if I wanted VRec on my Tele I would need an embedded and tiny OS and you're totally...

7 hours ago by dava4444 on How to build a GUI for a toaster
dava4444

Hi Adrian been trying to post for three days .this spam bot is a nightmare. Dava

7 hours ago by dava4444 on How to build a GUI for a toaster
dava4444

Hi James I totally agree. The new site makes me want to come and post, but the spam bot refers me at every turn. I even at one point, thought I...

7 hours ago by dava4444 on Spam? Filter Changed?
sameerhere

the future of mobile will be location and context aware. This means, you will have apps that will suggest you depending where you are right...

9 hours ago by sameerhere on Symbian^3 will do resistive multitouch, says Nokia
kenye2009

hello i would like to have some form of a answer to this question as it concerns the goverment i want to know why if your on state benefits as a...

9 hours ago by kenye2009 on ITN to launch ITV online news service

Featured white papers

Achieving PCI Compliance for:Privileged Password Management & Remote Vendor Access

For multi-store outlets, including retail, banking, grocery, gas, hospitality, convenience stores and others, reducing (or avoiding) the cost of in-store system support and maintenance while maintaining compliance with PCI and other requirements has become a strategic challenge.

Download now

Web 2.0 Security Threats: How to Protect Your Enterprise Network

Speaker: Dr. Chenxi Wang, Principal Analyst, Security and Risk Management, Forrester Research, Inc. As Enterprises are increasingly connected to the Internet and as hard organizational boundaries are fast disappearing, security professionals are facing fresh challenges in Enterprise computing.

Download now

MindManager - Tutorial for New Users - Short

This tutorial is for new MindManager users and teaches you how to get started, by creating maps, reading maps and organizing your information.

Download now