GNU/Linux vendors Debian, Mandrake, Red Hat, and SUSE have joined together to give a common statement about the Forrester report entitled "Is Linux more Secure than Windows?". Despite the report's claim to incorporate a qualitative assessment of vendor reactions to serious vulnerabilities, it treats all vulnerabilities as equal, regardless of their risk to users. . . .. GNU/Linux vendors Debian, Mandrake, Red Hat, and SUSE have joined together to give a common statement about the Forrester report entitled "Is Linux more Secure than Windows?". Despite the report's claim to incorporate a qualitative assessment of vendor reactions to serious vulnerabilities, it treats all vulnerabilities as equal, regardless of their risk to users. As a result, the conclusions drawn by Forrester have extremely limited real-world value for customers assessing the practical issue of how quickly serious vulnerabilities get fixed. The link for this article located at Debian.org is no longer available. . Linux distributors have collaborated to tackle issues identified in the Forrester analysis concerning Linux system safety.. Linux Security, Vendor Perspectives, Security Evaluation. . LinuxSecurity.com Team
Have you ever heard of a Linux vendor that tried to deny a security flaw in their open source product? "A number of Unix vendors have been alerted to a security flaw, but Sun Microsystems is refusing to acknowledge that any problem exists. Six vendors, including IBM, Hewlett-Packard and Sun, have been alerted to a vulnerability that ships with several Unix systems, which could allow a malicious attacker to take control of an affected system.. . .. Have you ever heard of a Linux vendor that tried to deny a security flaw in their open source product? "A number of Unix vendors have been alerted to a security flaw, but Sun Microsystems is refusing to acknowledge that any problem exists. Six vendors, including IBM, Hewlett-Packard and Sun, have been alerted to a vulnerability that ships with several Unix systems, which could allow a malicious attacker to take control of an affected system. Internet Security Systems (ISS) identified the Unix vulnerability about a month ago, and the company warned that the serious weakness could be found in six Unix vendors' systems. ISS and CERT (Computer Emergency Response Team) issued an advisory about the problem. While Caldera, Compaq and IBM said they had a patch for the problem, HP disagreed on the versions of its Unix flavour that needed the patch. The link for this article located at vnunet is no longer available. . Oracle Corporation refutes claims of a critical database vulnerability even after warnings from cybersecurity experts, prompting worries about the adequacy of incident management.. Unix Systems, Vendor Denial, Security Patch, Open Source Issues. . LinuxSecurity.com Team
Responding to an effort by Microsoft [NASDAQ:MSFT] to squelch the full disclosure of software vulnerabilities, a group of "white hat" hackers is putting out a call to other experts, asking them to deluge software vendors with bug reports. "Let's flood the security department of every vendor with new issues.. . .. Responding to an effort by Microsoft [NASDAQ:MSFT] to squelch the full disclosure of software vulnerabilities, a group of "white hat" hackers is putting out a call to other experts, asking them to deluge software vendors with bug reports. "Let's flood the security department of every vendor with new issues. Let's show the world what they would miss and what information could just as easily have stayed in the underground," wrote a security researcher who uses the nickname "HellNbak," in an announcement posted to several security mailing lists last week. So far, only one prominent organization has signed on to the "Information Anarchy 2K01" initiative - a group known as Nomad Mobile Research Center, of whom HellNbak is a member. The link for this article located at Newsbytes is no longer available. . Responding to an effort by Microsoft [NASDAQ:MSFT] to squelch the full disclosure of software vulner. responding, effort, microsoft, [nasdaq, msft], squelch, disclosure, software, vulner. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.