Comments on: IBM report: Vulnerabilities still going unpatched
IBM X-Force report finds many disclosed vulnerabilities are unpatched years later and that Microsoft is the vendor with the highest percentage of disclosed holes.
IBM X-Force report finds many disclosed vulnerabilities are unpatched years later and that Microsoft is the vendor with the highest percentage of disclosed holes.
Web sites launch all the time, but they also shut their doors. We highlight 15 that bit the dust this year.
Let the debate begin: Was the iPhone more important than iTunes? Was anything bigger than Google finding a great business model? CNET offers its list of the 10 most important stories of the '00s.
Online security is threatened by more than hacking and phishing attempts. Check here for the latest updates on software vulnerabilities, data leaks, and rapidly spreading viruses--and learn how to protect your systems.
Add this feed to your online news reader
Please clarify. Did you switch to a plain list of disclosed vulns at this point in the article, or did you mean to continue speaking of vulnerabilities disclosed *but not patched* ?
I assume so as Oracle, Mozilla, Drupal, Joomla! are on that list and they don't make operating systems.
If so, that is a meaningless unless it is divided by the amount of software measured. So Microsoft makes the top of the list because it makes a wide variety of software. I also assume some of the Linux vendors get a break here because many Linux vulnerabilities are non-vendor specific.
I would be more concerned about a vendor (Joomla!) that makes one product (a CMS) being only one percent behind a vendor like Microsoft that makes mobile, client & server operating systems, desktop applications, database servers, email servers, internet servers, browsers, a CMS (SharePoint), IDEs and other programming tools and runtimes, Mac software, Enterprise apps (Dynamics), security tools, entertainment software / games, etc.
It's not difficult to locate contact information. Google Security Project Name and links are at the top.
- Drupal - http://drupal.org/security
- Joomla! - http://developer.joomla.org/security.html
- Typo 3 - http://typo3.org/teams/security/
This is corporate bully-ism at it's finest. If IBM wants to increase software security, step one is contacting those people with these so-called known issues so that they can bring necessary improvements. Then, if your PR guys insist on credit, contact the media and blow your own horn.
For 25 years, I've always been a fan of Big Blue. Shame on you, IBM!
- by elinwaring February 4, 2009 2:54 AM PST
- The problem with this list, is that it punishes applications for disclosing vulnerabilities. The Joomla! project is committed to disclosing security issues along with providing patches as soon as we can when a vulnerability is brought to light. I am proud to say that Joomla! has 100% disclosure of vulnerabilities and 100% patched.
- Like this Reply to this comment
-
(8 Comments)Many of the vulnerabilities patched this year never resulted in a single problem because they were discovered by community members who brought them to the attention of the security team. That is how community driven open source development works. That is how transparency and education about security makes applications more secure. Openness is also how we get our user community to understand the need to update when a security release is made. Being open with our user and developer community about issues that are discovered is a good thing, and I cannot understand why IBM would seek to discourage it.
For a great example of how open source projects such as Joomla! respond to security issues, take a look at this article.
http://developer.joomla.org/coordinator-blog/245-how-joomla-156-came-about.html
From the last lines
Total time from report of vulnerability to initial release: 2 hours 50 minutes
Total time from report of vulnerability to completion of release cycle completion: 3 hours 40 minutes
Total number of people directly involved: between 20 and 30
I think Joomla! has plenty to be proud of when it comes to how it handles vulnerabilites.