• Advertising
  • Advice
  • Affiliate Programs
  • Auto
  • Awards
  • Business
  • Careers
  • CGI
  • Computers
  • Communication
  • Copywriting
  • CSS
  • DHTML
  • Direct Mail
  • Domain Names
  • EBooks
  • ECommerce
  • Education
  • Email
  • Entertainment
  • Environment
  • Family
  • Finance
  • Fitness
  • Food
  • Free
  • Gardening
  • Government
  • Health
  • Hobbies
  • Home Business
  • Home Repair
  • HTML
  • Humor
  • Internet
  • Javascript
  • Law
  • Link Popularity
  • Management
  • Marketing
  • Marriage
  • Metaphysical
  • MLM
  • Motivational
  • Multimedia
  • Newsletters
  • Off-Line Promotion
  • Online Promotion
  • Other
  • Pets
  • Politics
  • Psychology
  • Publishing
  • Religion
  • Sales
  • Scams
  • Science
  • SE Optimization
  • SE Positioning
  • SE Tactics
  • Self Help
  • Sexuality
  • Site Security
  • Social Issues
  • Spam
  • Sports
  • Technology
  • Traffic Analysis
  • Travel
  • Viral Marketing
  • Web Hosting
  • Web Design
  • Webmasters
  • Weight Loss
  • Women's Issues
  • Writing
  • Product Review
  • Life Style
  • Celebrities
  • Online Business
  • Self Improvement and Motivation

  • COVERITY CATCHES BIGGEST X WINDOW SECURITY HOLE SINCE 2000

    Research contract from US Department of Homeland Security results in rapid fix to ?worst case scenario? security vulnerability in critical software system

    SAN FRANCISCO, May 2, 2006 ? Coverity, Inc., makers of the world?s most advanced and scalable source code analysis solution, today announced that as a result of their contract with US Department of Homeland Security (DHS), the biggest X Window System security vulnerability of the last six years was identified and fixed.

    Using Coverity Prevent, developers tracked down a critical security vulnerability in the X Window System, a graphical interface used in millions of computers, including most UNIX and Linux systems. The X Window System also ships as an optional GUI with Macintosh computers from Apple.

    According to Daniel Stone, a release manager for the X.Org Foundation, the vulnerability was one of the most significant vulnerabilities discovered in recent memory, ?something that we find once every three to six years and is very close to X?s worst case scenarios in terms of security. Coverity exposed vulnerabilities in our code that likely wouldn't have been spotted with human eyes. Its attention to subtle detail throughout the entire codebase ? even parts you wouldn't normally examine manually ? makes it a very valuable tool in checking your codebase, and has been of definite benefit to X.Org.?

    The vulnerability was found in versions X11R6.9.0 and X11R7.0.0 during a security analysis of 31 major open source projects that Coverity undertook as part of a DHS initiative. This pair of X Window System versions marked a major milestone when released in December of 2005, as they were the first major updates to the X Window System in more than a decade. After the X.Org development team received the results of the analysis, the vulnerability was fixed within a week. The security hole resulted from a missing parenthesis on a small piece of the program that checked the ID of the user. This flaw, caused by something as seemingly harmless as a missing closing parenthesis, allowed local users to execute code with root privileges, giving them the ability to overwrite system files or initiate denial of service attacks.

    ?Coverity Prevent is designed to help computer programmers automatically detect and remove software defects such as security vulnerabilities as the software is being built,? said Ben Chelf, CTO of Coverity. ?We?ve implemented a system to analyze the X Window System on a continuous basis to help prevent new defects from entering into the project. In my experience, the X.Org team responded to defects extremely quickly to make their high quality software even better.?

    ##

    About Coverity
    Coverity (www.coverity.com), makers of the world's most advanced and scalable source code analysis solution for pinpointing software defects and security vulnerabilities, is a privately-held company headquartered in San Francisco. Coverity was founded in 2002 by leading Stanford University computer scientists whose four-year research project resulted in a breakthrough technique to address the costliest problem in the software industry. That research breakthrough allows developers to quickly and precisely eliminate software defects and security vulnerabilities in tens of millions of lines of new or legacy code. Today, Coverity's solution is used by more than 100 leading companies to significantly improve the quality and security of their software, including Juniper Networks, Symantec/VERITAS, McAfee, Synopsys, NASA, PalmOne, Sun Microsystems and Wind River.

    Coverity is a registered trademark, and Coverity Extend and Coverity Prevent are trademarks of Coverity, Inc. All other company and product names are the property of their respective owners.

    Media Contacts
    Craig Oda
    Page One PR for Coverity
    coda@pageonepr.com
    +1 650 565 9800 x102

    Russ Wood
    Director, Corporate Marketing
    rwood@coverity.com
    +1 415 694 5304



    More articles:
    Giclee printing advantages

    Five Band Resistor Color Code-What Does The Last Band Of White Color Represent?

    Digital Picture Frames: The Wave of The Future

    Fire Department - Know How To Fireproof Your Data Center

    Consider An Emergency Generator

    Electronic Schematics Diagram-The Four Commonly Asked Questions

    Relieft from Sarbanes-Oxley on the way?

    Rear Projection TV Facts - Pros & Cons of Rear Projection in the Home Theater

    Digital SLR Camera versus a Compact Digital Camera

    Rename all windows files and folders

    Do I really need that Waterproof Digital Camera?

    Cell Phones Accessories - Second To Barbie

    File Security Manager 1.6 Released by UNGSoft

    World innovation with TerraSip mobile VoIP

    No More Distractions with Noise Reduction Headphones

    Mobile phone Hire

    Mobile phone Hire

    DSMax Radios

    Open Source Management Tools to Watch: Ganglia

    SWsoft Recruits Former VMware Manager as Director of Enterprise Channel Sales

    advanced



       Reviews phones mobiles
       Free games
       Anunturi masini second hand
       Ziarul Buna ZIUA IASI
       International News
       Matrimoniale
       Auto-Dealer.RO
       website value
    Home     About Us     Services     Products     Support     Contact
    © Article Storage 2006
    Hyundai Elantra Coupe  Nissan NISMO 370Z Facelift  Ford Shelby GT500  Audi R8  Mercedes B Class Brabus Tuning Package  Fiat Freemont AWD European Version