Who gets CERT's attention
[Posted November 23, 2004 by corbet]
Backers of proprietary software have, at times in the past, resorted to
claims that Linux and free software are the subject of more CERT advisories
than other systems. Such claims have been strikingly absent recently.
Since our detractors have apparently been too busy to tally up CERT's
output this year, we've decided to do it for them. Here's the full list of
CERT's 2004 "technical cyber security alerts":
| ID | Date | Vulnerability | Linux |
Windows | Other |
| TA04-028A |
Jan 28 |
MyDoom.B virus |
|
 |
|
| TA04-033A |
Feb. 2 |
Multiple Internet Explorer holes |
|
 |
|
| TA04-036A |
Feb. 5 |
Check Point Firewall HTTP parsing |
|
|
 |
| TA04-041A |
Feb. 10 |
Multiple ASN.1 holes |
|
 |
|
| TA04-070A |
Mar. 10 |
Outlook mailto: handling vulnerability |
|
 |
|
| TA04-078A |
Mar. 19 |
Multiple OpenSSL vulnerabilities |
 |
|
|
| TA04-099A |
Apr. 8 |
Outlook Express MHTML cross-domain |
|
 |
|
| TA04-104A |
Apr. 14 |
Multiple vulnerabilities in Microsoft products |
|
 |
|
| TA04-111A |
Apr. 20 |
TCP/BGP session termination |
 |
|
 |
| TA04-111B |
Apr. 20 |
Cisco IOS SNMP message handling |
|
|
 |
| TA04-147A |
May 26 |
CVS heap overflow |
 |
|
|
| TA04-160A |
Jun. 9 |
Oracle SQL injection |
|
|
 |
| TA04-163A |
Jun. 11 |
Internet Explorer cross-domain redirect |
|
 |
|
| TA04-174A |
Jun. 22 |
Multiple DHCP vulnerabilities |
 |
|
|
| TA04-184A |
Jul. 2 |
Internet Explorer ADOBD.Stream control |
|
 |
|
| TA04-196A |
Jul. 14 |
Multiple Windows/Outlook vulnerabilities |
|
 |
|
| TA04-212A |
Jul. 30 |
"Critical" Windows/IE remote code execution |
|
 |
|
| TA04-217A |
Aug. 4 |
Multiple libpng vulnerabilities |
 |
|
|
| TA04-245A |
Sep. 1 |
Multiple Oracle vulnerabilities |
|
|
 |
| TA04-247A |
Sep. 3 |
MIT Kerberos 5 |
 |
|
|
| TA04-260A |
Sep. 16 |
Microsoft JPEG component |
|
 |
|
| TA04-261A |
Sep. 17 |
Multiple Mozilla vulnerabilities |
 |
|
|
| TA04-293A |
Nov. 10 |
Multiple Internet Explorer vulnerabilities |
|
 |
|
| TA04-315A |
Nov. 11 |
Internet Explorer buffer overflow |
|
 |
|
| TA04-316A |
Nov. 11 |
IOS input queue vulnerability |
|
|
 |
|
|
TOTALS: |
7 |
13 |
6 |
Now, one can raise all sorts of complaints about this table. The logic
that assigns the Mozilla vulnerability to Linux could also, easily, have
charged it to Windows as well. The process by which CERT chooses
vulnerabilities worthy of "cyber security alerts" is poorly understood.
And so on.
There are seven vulnerabilities in the Linux column - and that is seven too
many. But that is far less than the count in the proprietary columns. The
Windows vulnerabilities include many which affect a large percentage of
users; instead, very few users were affected by most of the Linux
problems. The CERT advisory count is a flawed measure at best, but, within
its limits, it shows that things could be a lot worse.
(
Log in to post comments)