Welcome | Sign In
TechNewsWorld.com
Bugs

Coverity Certifies 11 Open Source Bug Hunters

Print Version
E-Mail Article
Reprints
Coverity Certifies 11 Open Source Bug Hunters

With a grant from the Department of Homeland Security, security firm Coverity has been scanning open source security software for holes since 2006. In the hundreds of projects scanned, the project has fixed 7,500 holes, according to Coverity. Open source projects analyzed at the site include some of the world's most widely used applications, including the Apache Web server and Firefox.


Think you have to compromise on security to save on costs? Think Again. Trend Micro™ Enterprise Security, powered by the Trend Micro Smart Protection Network™, can lower your content security management costs by up to 40%. Find out just how much you’ll save with our TCO Impact Calculator.

San Francisco-based security firm Coverity has been working with support from the U.S. Department of Homeland Security (DHS) and with Stanford University to find flaws in open source software, and it looks like they've found plenty.

Since March 2006, an online Coverity software scanning site has analyzed 50 million lines of software in more than 250 projects, which ultimately led to 7,500 software defect fixes, 6,000 of which occurred in the first year.

The scanning comes courtesy of a DHS grant that's part of the federal government's Open Source Hardening Project. The project is designed to make open source software more secure for businesses and government agencies that utilize it.

Movin' On Up

More importantly, Coverity announced this week that 11 popular open source projects have graduated to "rung 2" of Coverity's open source security ladder, which means basic security vulnerabilities have been fixed and the developers of the project have built up experience with Coverity's Prevent toolset. At rung 2, the open source projects will benefit from more thorough testing using Coverity's upgraded scanning solutions, which can root out hard-to-find defects.

The 11 projects are Amanda, NTP, OpenPAM, OpenVPN, Overdose, Perl, PHP, Postfix, Python, Samba and TCL.

"We applaud the developers responsible for the 11 open source projects that have advanced to the second rung of code security and quality at the Coverity Scan site," noted David Maxwell, open source strategist for Coverity.

In addition to the 11 projects, additional open source projects are poised for advancing to rung 2 over the next months.

Popular Projects

Open source projects analyzed at the site include some of the world's most widely used applications, including the Apache Web server, the Linux operating system, the Firefox browser and the Samba file and printer sharing system, Coverity said.

The company noted that hundreds of open source developers have integrated the use of Coverity's technology into their open source development process to improve software quality and security.

Intrinsic Flaws?

The obvious question is, are open source projects more likely to have security weaknesses than commercial software?

"The research varies. Closed source software advocates will tell you that the lack of available source code as well as commercial interests result in more secure products, while open source software advocates will tell you that many eyes make for shallow bugs, and that patch speed is dramatically increased," Stephen O'Grady, an analyst for RedMonk, told LinuxInsider.

"Ultimately, my view is that all software -- closed or open -- will have vulnerabilities. But nothing I've seen has led me to believe that open source software is intrinsically less secure," he added.

The Coverity Scan site is freely available to qualified open source projects.


Print Version E-Mail Article Reprints More by Chris Maxcer


More by Chris Maxcer

Let's Give the iPhone Hackers a Big Round of Applause
November 06, 2009
It's safe to say most Apple customers are satisfied living in the walled-off ecosystem that the company has created for products like the iPhone. Still, it's good to know that it is possible -- and relatively easy, even -- to bust through those walls if one should ever want to. The work of iPhone hackers is appreciated even by those who've never felt the jailbreak itch.
What the iPhone Needs to Keep the Android Hordes at Bay
October 30, 2009
The Android platform is growing fast, and Verizon is readying what may be the best Android phone yet. Consumers are getting more Android options on more networks. Meanwhile, Apple is sticking to a consistent device design on a single network. The iPhone doesn't need to branch off into multiple sizes and styles to be the dominant platform, but its single-U.S.-carrier situation is another story.
Apple Is Saving the Best for Last
October 23, 2009
Sifting through the language used in Apple's quarterly results conference calls can sometimes yield clues to the highly secretive company's next moves. Apple's latest phone chat with analysts included a few comments about December shipping costs and a mystery "product." Here's why we might see an Apple tablet before the new year.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network