All the latest UK technology news, reviews and analysis

Fans should 'weep' over Linux bugs

by James Middleton

08 Feb 2002

Be the first to comment

  • Tweet this

Following the furore earlier this week over which operating system, Linux or Windows, suffered more security vulnerabilities throughout 2001, Linux site LWN.net set about comparing the vulnerabilities suffered by different Linux distros in 2001.

Needless to say, the results were quite interesting, even prompting the Linux site to warn: "Anybody who is proud of Linux's security should have a good look and weep - it is a very long list."

The big picture is somewhat vague, because although all Linux distributions have the same kernel, each distro contains thousands of different packages and extra applications.

LWN said: "There is no end of caveats that apply to this table: it is hard to make a one-for-one comparison of security updates across distributions. Undoubtedly some updates have been joined that should not be, and others have been kept separate when they should be together."

Also, the results do not distinguish between versions, so an update for Red Hat 6.2 would be lumped in with Red Hat in general.

The resulting table identifies 290 updates for 145 unique vulnerabilities across the main Linux distributions - Suse, Debian, Mandrake, Red Hat and TurboLinux.

"It would seem that the vnunet.com article actually underestimated the problem," said LWN.

However, in light of the results, the site was quick to point out that "we are not yet at a point where we can make meaningful comparisons even between Linux distributions. Trying to compare Linux with Windows seems like a waste of time."

The fact that each distribution of Linux comes with a wide assortment of packages makes it more than just an operating system for comparison purposes. And the scope of difference between each distro is so wide that patches released for a package in one distro may not be at all applicable to another.

"In the end, there is only so much to be learned about the security of an operating system by counting its published vulnerabilities," said LWN.

"One has to look at the seriousness of each, how it was discovered (internal audit or external exploit), how long users had to wait for a fix, and how many users were actually compromised as a result of the problem. We need better ways of understanding and comparing security response; simply counting vulnerabilities is not sufficient."

Below is the table identifying all Linux security updates throughout 2001 for the major distros.

Linux security updates in 2001
Vulnerable packageDebianMandrakeRed HatSuSETurbolinux
analogX   X
apache (Jan)XX   
apache (Jul)XXX  
arpwatch X   
bindXXXXX
cfingerd (Apr)X    
cfingerd (Jul)X    
cronXXXXX
ctagsX    
cups X X 
cvsweb    X
cyrus-sasl  XX 
dhcp    X
dialog    X
diffutils XX  
ed    X
ePerlXX X 
elm X   
esound    X
eximX X  
exmhXX   
expect X   
fetchmail (Jun)XX   
fetchmail (Aug)XXXX 
fmlX    
gdm X   
getty_ps X   
gftp (May)XXX  
gftp (Oct)X    
glibc (Mar)XXX X
glibc (Dec) XXX 
gnupgXXXXX
gnuservX    
gpmXX   
groffX    
gtk+ X  X
htdigXXXX 
hylafax X X 
icecastX X  
imap X X 
impX    
inetd  X  
innXX   
iptables  X  
ispell XX  
jazipX    
joeXXXX 
kdelibs XX  
kdesu X X 
kernel (May)   X 
kernel (Oct)XXX X
kernel (Nov) XXX 
ld-linux   X 
libgtop X   
licq X   
linuxconf X   
losetup  X  
lpr  XX 
lprng  X X
mailmanX X  
mailxX    
man (May)X XX 
man (Feb)X    
man2htmlX    
mcX  X 
mesa X   
mgettyXXX X
micqX X  
minicom XX  
mktemp  X  
mod_auth_pgsql  X  
mod_auth_mysql   X 
mostX    
mutt XX  
mysqlXX   
ncurses X  X
neditXXXX 
netscapeXXX X
nfs-utils    X
ntpdXXXXX
ntping   X 
nviX    
omni print  X  
openldapXX   
openssh (Jan)X    
openssh (Feb)XX XX
openssh (Oct) X   
openssh (Dec)XXXX 
openssl XX X
php4XX   
pine X   
pmake    X
postfixXX   
printtool  X  
procmailXXX  
proftpd (Feb)XX   
proftpd (Mar)X    
rdist X   
rpmdrake X   
rxvtX    
samba (May)XX   
samba (Jun)XXXX 
sashX    
screen   X 
sdbsearch   X 
sendfileX    
sendmailXXXXX
sgml-toolsXXXX 
shadow-utils X   
slocate    X
slrn (Sep)X    
slrn (Mar)XXX  
snmp  X  
splitvtX    
squid (Jan)XX  X
squid (Jul)XXXX 
sudoXXXX 
susehelp   X 
tcpdump X  X
telnetXXXX 
tetex XX  
timed X X 
tinyproxyX    
tripwire X   
util-linux X X 
uucpXX X 
vim XXXX
w3m (Jun)X    
w3m (Oct)X    
webalizer  XX 
webmin X   
wmakerXX X 
wmtvX    
wu-ftpd (Nov)XXXX 
wu-ftpd (Jan)XX  X
XawX    
xemacs XX X
xfree86X X  
xinetdXXXX 
xloadimageXXXX 
xmcd   X 
xtelX    
xvtX    
zope (May)XXX  
zope (Mar)XX   
Totals:8181564428

Source: LWN.net

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

31%

1%

12%

56%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Test Architect

Are you looking for a new positing within the Testing...

B2B Marketing Executive

A leading global provider of critical information to...

Scrum Master

Want to work for one of the most dynamic, creative environments...

Interactive & Mobile QA Engineer

Want to work for one of the most dynamic, creative environments...

To send to more than one email address, simply separate each address with a comma.