Security Innovation's Microsoft/Linux web server security study
[Posted March 23, 2005 by corbet]
Security Innovation has
announced the availability of its (Microsoft-funded) web server security survey which found Windows to be a more secure platform. The document itself is available
in PDF format. "
For example, CAN-2004-0957 discusses a bug in MySQL's mysql_real_connect()
function. This was entered into the MySQL bug database on 4th June 2004, and fixed in
the source tree 17th June 2004. However, Red Hat only packaged this fix in RHSA-2004:611, issued on the 27th of November. This problem of the management of fixes
from a third-party is a difficult one, and one which could represent a significant challenge
to Linux on a go-forward basis."
(
Log in to post comments)