Categories
View
Poll
Refurb

Top Five Applications With Critical Security Vulnerabilities: Ridiculous

By linathael. Original by Lionel - 23/06/2006 14:31:47 CEST - Category: Internet
The market for IT security is large, but very competitive, especially for WinTel system. Almost everyday, an IT Security Company is trying to promote its solutions by releasing PR claiming heaven while basically they do not report anything new. Today, the company Bit9 has found a new way to promote its "award-winning solutions" by designing characteristics in order to generate new listing of top applications with known vulnerabilities. Amazing but true... so the following parameters have been selected:
- is well-known in the consumer space and frequently downloaded by individuals;
- is not classified as malicious software by enterprise IT organizations;
- contains at least one critical vulnerability registered in the U.S. National Institute of Standards and Technology's (NIST) official vulnerability database;
- has a severity rating of between 7.0 - 10.0 (high) on the CVSS scoring system;
- relies on the end user, rather than a central administrator, to manually patch or upgrade the software to eliminate the vulnerability, if such a patch exists.

So of course with such settings, the top 5 applications with critical security vulnerabilities is quite unusual:
1. Mozilla Firefox 1.0.7
2. Apple iTunes 6.02 et Quicktime 7.0.3
3. Skype Internet phone1.4
4. Adobe Acrobat Reader 7.02, 6.03
5. Sun Java Run-Time Environment 5.0 Update 3, JRE 1.4.2_08
All those applications have security updates available and then can be patched, the main reason for them to be listed in the top five, is the last parameters of the settings: "relies on the end user, rather than a central administrator, to manually patch or upgrade the software to eliminate the vulnerability, if such a patch exists"
As a result, such analysis does not pick up any MS applications, even tough it is well known that MSN for example is a real plague for IT security, but MS provides automatic updates...
Oups… they also forgot to take into account that in big Corporate Companies, users do not have administrative rights on their computers, so such applications are either not installed or updated by the local IT group…
In addition, the website reporting this news,ITNEWS, has its front page covered by ads promoting Microsoft protection and security system against Malwares...
Please, but could companies be serious when talking about serious problems??

News
Articles
Blog
All Keywords
From
To
Full View
Daily View
List View
Next
Previous
Printer Friendly
Tip a friend
Share this page