Secunia: More Red Hat flaws than Microsoft in 2007

By Tom Espiner, ZDNet UK
Thursday, January 17, 2008 10:35 AM

Danish vulnerability research company Secunia has said there were more flaws reported for Red Hat operating systems than for Microsoft operating systems in 2007.

In a paper entitled Secunia 2007 Report that was made available to Secunia customers on Monday, the company compared last year's vulnerability reports for five operating systems: Microsoft Windows (98 and onwards); Mac OS X; HP-UX 10.x and 11.x; Solaris 8, 9, and 10; and Red Hat (excluding Fedora).

The company found that Red Hat had the most reported vulnerabilities out of those operating systems, with 633 flaws. Solaris had a total of 252 vulnerabilities, while Apple Mac OS X came third with 235. Windows came fourth with 123, while HP-UX had 75 reported flaws.

However, Red Hat Security Team director Mark Cox denied that the vulnerability count was as high as 633 for Red Hat, instead claiming 404 vulnerabilities in 2007.

"Secunia released a security summary report for 2007 and surprisingly gave a count for Red Hat for the year at over 600 vulnerabilities," said Cox. "I've no idea how they got to this number, it certainly doesn't match our metrics. For every Red Hat product and service for 2007 we issued 306 advisories to fix 404 vulnerabilities. Of those 404 vulnerabilities 41 were critical."

Most people would not be using every Red Hat product, said Cox. Taking just Red Hat's Enterprise Linux product, there were 48 vulnerabilities, of which 27 were critical, Cox said.

Cox added that a raw count of vulnerabilities "isn't much use and is only a small part of the overall risk exposure in using a product".

Secunia said that while Red Hat had more reported vulnerabilities than Windows, it was not possible to compare its relative security with Microsoft products, or comment on the relative security of open-source versus proprietary products based on vulnerability figures.

"It's impossible to make a fair comparison--it's like comparing apples to oranges," Thomas Kristensen, Secunia's chief technology officer, told ZDNet.co.uk. "Red Hat has the highest number of applications included, so the number of vulnerabilities that affect it is bound to be higher."

Red Hat contains two different browsers and graphic interfaces, as well as a number of PDF readers and image editors, said Secunia. Red Hat, HP-UX and Solaris can be used as servers, so include and support a large number of third-party components, while "the same cannot be said of all versions of Windows and Mac OS X", Secunia explained.

"Web servers, database servers, archiving tools, office productivity suites--there's two of everything when it comes to Red Hat," said Kristensen. "Windows XP can only be used as a workstation. If you want to run XP as, say, a web server, you have to buy either Microsoft or third-party software."

Kristensen said that third-party software was a key factor affecting the number of vulnerabilities attributed to the respective operating systems. With Red Hat, 99 percent, or 629 of the vulnerabilities, were due to third-party components. With Windows, four percent of flaws were due to third-party software.

One of the differences between the operating systems, said Kristensen, was that Red Hat notified customers of third-party flaws that affected its operating systems, as well as supporting them. Microsoft, on the other hand, only notified customers of flaws within its control.

"If you don't have to install third-party tools on Red Hat systems, it's easier to know about vulnerabilities," said Kristensen. "With Microsoft, you have to get Microsoft bulletins, Apple bulletins, Adobe bulletins--wherever you got the software from." Kristensen added that the time taken to patch critical, publicly disclosed vulnerabilities was also much longer for Microsoft systems, compared with open-source software.

"The general trend is that critical issues in open-source applications have a much shorter patch time compared with Microsoft," said Kristensen. "For irresponsibly disclosed flaws, patching time is critical. Microsoft is a very big company with a certain level of bureaucracy--only Microsoft can fix patching errors. There's a quality assurance testing period before a patch is available. With open source, if there's an incompatibility with a patch, you can change the code. There's an open dialogue with a community, and you can fix it from there."


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Export project data for future effort estimation

Tech Management

Learn to tweak your estimation matrix even further by analyzing the project data from your Microsoft Project schedule.


Read more »



 
Virtualize your way to cost savings
Build an infrastructure that is flexible, scalable, and economical, as you strive to become a truly agile business.

Red Hat Outlines Its Virtualization Strategy and Roadmap for 2009
» Watch the video




Are telcos new drivers of outsourcing industry?

Blog thumbnail

The recent TPI Index from TPI highlighted an interesting trend where a few very large telco-to-telco contracts--instances where one telecommunications carrier outsources its network operations requirements to another telecommunications service..... by Michael Rehkopf

Read more »

Tags

  1. antivirus
  2. apple ipod
  3. cnet networks inc.
  4. desktop
  5. e - mail
  6. hard drive
  7. intuit inc.
  8. mcafee inc.
  9. microsoft corp.
  10. microsoft windows
  11. microsoft windows vista
  12. microsoft windows xp
  13. norton co.
  14. pc
  15. performance
  16. security
  17. software
  18. tool
  19. web
  20. web site