Language Selection

English French German Italian Portuguese Spanish

Top FOSS security vulnerabilities

Filed under
Security

Palamida, the San Francisco company that helps companies to audit their use of open source software, has released a list of what it calls "the top five most overlooked open source vulnerabilities." To this list, Palamida has added an additional five vulnerabilities exclusively for Linux.com.

The list is partly a promotion of Palamida's Vulnerability Reporting Solution, which recently added 431 security alerts based on National Vulnerability Database listings. However, the list is also designed to draw attention to the lax practices surrounding the use of open source software in business, according to Theresa Bui, co-founder and vice president of marketing at Palamida.

To be precise, the vulnerabilities on the list are based on Palamida's audits of its clients. These audits vary from scans of a few hundred megabytes of code to hundreds of gigabytes in a company's complete software infrastructure. The list summarizes the results of scanning 3-5 million lines of code, representing a minimum of 30% of a company's software assets and, more often, at least 50%.

More Here




More in Tux Machines

Google launches new site to showcase its open source projects and processes

Google is launching a new site today that brings all of the company’s open source projects under a single umbrella. The code of these projects will still live on GitHub and Google’s self-hosted git service, of course, with the new site functioning as a central directory for them. While this new project is obviously meant to showcase Google’s projects, the company says it also wants to use it to provide “a look under the hood” of how it “does” open source. Read more

Tizen and Android

Day of Infamy, CRYENGINE, and Performance Tools

Red Hat: We're giving VMware a 'run for its money' in virtualization

Red Hat's enterprise virtualization product is proving stiff competition for VMware, Paul Cormier, EVP and president of products and technologies, claimed at Red Hat's North American Partner Conference in Las Vegas, Nevada yesterday. According to the executive, Red Hat Virtualization (RHV), the open source software vendor's mission-critical, end-to-end open source virtualization infrastructure, has made a name for itself in such a way that VMware customers are increasingly showing interest in the technology. Read more Also: Red Hat CEO says businesses remain confident under Trump Amazon, Red Hat, Tesaro Price Targets Raised; Snap Started At Hold Tech Today: Snap’d By Facebook, Apple’s Innovation, Red Hat Jumps