Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Microsoft > Patches and Vulnerabilities

October 17th, 2007, 10:49 GMT · By

Microsoft: Linux - 1,000+ Security Vulnerabilities - No Match for Vista

SHARE:

Adjust text size:


Windows Vista
Enlarge picture
According to Microsoft, one distribution of Linux passed the 1,000 security vulnerabilities milestone in just over two years on the market. Linux, alongside the UNIX-based Mac OS, are operating systems perceived as secure by default, and at the opposite pole of what Microsoft is offering with Windows. The perception extends to the perspective where Linux is not only an epitome of security but also a foolproof product. This is of course not the case. There is no silver bullet solution for security, and in this respect, the code of Mac OS X, Linux and Windows
is equally vulnerable, via software design flaws.

Ever since Windows Vista hit the shelves in January 2007, Jeff Jones, Microsoft Strategy Directory Security Technology Unit, began compiling monthly Operating System Vulnerability Scorecards, indicating the evolution of the volume of security flaws in Windows Vista, Windows XP, Mac OS X 10.4 Tiger and Linux distributions from Red Hat, Canonical and Novell. In the first seven months of 2007, Mac OS X 10.4 Tiger cumulated in excess of 130 vulnerabilities, Red Hat Enterprise Linux 5 Desktop also accounted for approximately 130 flaws, with Novell SUSE Linux Enterprise Desktop 10 going as high as 145 security holes, followed by the Ubuntu distribution of Linux with over 150 and Red Hat Enterprise Linux 5 Workstation with 180.

Of course that the actual volume of vulnerabilities is by no means a comprehensive measure of security. In fact, security flaws are merely an aspect of the overall level of protection delivered by a specific product. Security is essentially a combination of multiple factors such as code quality (the lack of vulnerabilities), an immature threat environment (lack of malicious code designed for a piece of software or a platform) and a market position that catalyzes little to no exploits. Although Linux and Mac OS X are impacted by a consistent number of vulnerabilities, there is virtually no malware affecting the two operating systems, as both platforms have an obscure market share. The same is not valid for Windows, dominating over 93% of the operating system market.

However, Jones downplayed Linux security, underlining the immense mass of vulnerabilities plugged by Red Hat in over two years for a single distribution of the Linux operating system. "According to my calculations, in July 2007, the Red Hat Enterprise Linux 4 team fixed their 1000th unique security vulnerability. Now, 164 of these were Low severity and 479 were Medium severity, but still, that is a ton of work accomplished by that team, especially given that the product only shipped in February of 2005. To put that in context, (again by my calculations) Microsoft has fixed only 649 security vulnerabilities for all supported products across the company since the year 2000", Jones stated. (emphasis added)

TELL US WHAT YOU THINK:

3,016 hits · 1 comment · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Linux Is Copying Windows Vista

Ubuntu Linux Kicks Windows Vista

Mac OS X and Linux Fail to Compare to Vista

Scrap Mac OS X and Linux - It's Windows Vista All the Way!

Microsoft Drives Linux Adoption - Vista Didn't Do It!

READER COMMENTS:


Comment #1 by: cyber_rigger on 17 Oct 2007, 14:45 UTC reply to this comment

Talk about comparing apples to oranges!

Some Linux "distributions" have 20,000 software packages.

To compare this to a stock Vista install is ridiculous!

Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM