A majority of the open source codebases found in commercial applications analyzed by Synopsys contained security vulnerabilities. . Applications that use open source code offer a host of benefits, including transparency, flexibility, cost effectiveness and community support. But how do such products fare on security? Though the community-based approach toward open source means that security flaws should be identified quickly, patching those flaws and applying the patches is another matter. . Public domain software fosters openness, adaptability, and economic advantages, although they face challenges regarding protection to tackle.. Open Source Security, Commercial Applications, Security Challenges. . LinuxSecurity.com Team
On the surface, it was just another turn of the endless cycle of software release, hole discovery, and patching: operating system vendor Red Hat issued an advisory Tuesday warning the world about a serious security hole in a file transfer program . . . . On the surface, it was just another turn of the endless cycle of software release, hole discovery, and patching: operating system vendor Red Hat issued an advisory Tuesday warning the world about a serious security hole in a file transfer program that comes with Linux, and urged customers to download a patch. There was just one problem: Red Hat's advisory jumped the gun on what was intended to be a simultaneous multi-vendor release, carefully coordinated by the government-funded Computer Emergency Response Team (CERT), and scheduled for December 3rd. Caught off guard, other Linux vendors were rushing Wednesday to finalize their own patches for the hole-- a memory-allocation bug in the ubiquitous Washington University WU-FTPd program. The link for this article located at SecurityFocus is no longer available. . On the surface, it was just another turn of the endless cycle of software release, hole discovery, a. surface, another, endless, cycle, software, release, discovery. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.