{"id":27361,"date":"2014-11-13T04:40:26","date_gmt":"2014-11-13T09:40:26","guid":{"rendered":"http:\/\/www.opensource.im\/?p=27361"},"modified":"2014-11-13T04:40:26","modified_gmt":"2014-11-13T09:40:26","slug":"coverity-security-report-open-source-projects-severely-in-need-security-programs","status":"publish","type":"post","link":"https:\/\/euvolution.com\/open-source-convergence\/open-source-software\/coverity-security-report-open-source-projects-severely-in-need-security-programs.php","title":{"rendered":"Coverity Security Report: Open source projects severely in need security programs"},"content":{"rendered":"<p><p>    In    todays IT environments, security has become a major concern.    Despite recent reports of software vulnerabilities in open    source code, including Shellshock, the OpenSSL Heartbleed and GoToFail, companies still    prefer to use open source software.  <\/p>\n<p>    But, open source developers dont always adhere to best    practices when it comes to security such as conducting regular    security audits and using static analysis, found     Coverity Inc.s Spotlight report. The Coverity Scan    Security Spotlight identifies several common defects and    exposures (CVEs) in open source code, and identifies that the        GoToFail vulnerability could have been detected in the    scan.  <\/p>\n<p>    The provider of     application development testing added its Security Advisor    to the Coverity Scan service, which resulted in the discovery    of almost 4,000 defects. Almost 2400 of these were high    severity defects, followed by 1330 low severity and 260 and so    medium severity.  <\/p>\n<p>    The Coverity Scan service analyzed several hundreds of millions    of lines of code from more than 1,500 open source projects     including C\/C++ projects such as NetBSD, FreeBSD, LibreOffice    and Linux, and Java projects such as Apache Hadoop, HBase and    Cassandra.  <\/p>\n<p>    The scan also detected 688 Open Web Application Security    Project (OWASP) Top 10 issues in 37 open source projects,    including big data, network management, and blog server    projects. The top 10 issues found on the scan are injection,    broken authentication and session management, cross-site    scripting (XSS), insecure direct object references, security    misconfiguration, sensitive data exposure, missing function    level access control, cross-site request forgery (CSRF), using    components with known vulnerabilities, and unvalidated    redirects and forwards.  <\/p>\n<p>    The road to application quality and security starts in    development,     said Zack Samocha, senior director of products at Coverity.    With three major security issues related to open source code    defects this year, its imperative that open source developers    design code security into their projects starting as early as    possible  <\/p>\n<p>    That means utilizing security experts to help, adds Samocha.    Vulnerable areas in code arent always immidiately obvious and    how attackers will use them is even less obvious at the    developer level. Most code bugs dont even become a problem    until code is being executed in production; after its released    from the sanitary world of the development environment.  <\/p>\n<p>    The solution: regular security audits and in-depth    vulnerability exams that try to suss out the problems before    theyre exploited.  <\/p>\n<p>    There have been several highly publicized open source    vulnerabilities this year alone, including     Heartbleed and     Shellshock. Those two flaws impacted a large number of    users because of the widespread implementation of open source    software.  <\/p>\n<p>    Coverity introduced its monthly Coverity Scan Project    Spotlights due to high demand for the annual Coverity Scan    Report and the insight it provides into the state of    open-source software quality. The Coverity Scan Report has    become something of a standard for measuring the state of    open-source software quality.  <\/p>\n<p><!-- Auto Generated --><\/p>\n<p>Original post:<br \/>\n<a target=\"_blank\" href=\"http:\/\/siliconangle.com\/blog\/2014\/11\/12\/coverity-security-report-open-source-projects-badly-need-security-programs\" title=\"Coverity Security Report: Open source projects severely in need security programs\">Coverity Security Report: Open source projects severely in need security programs<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> In todays IT environments, security has become a major concern. Despite recent reports of software vulnerabilities in open source code, including Shellshock, the OpenSSL Heartbleed and GoToFail, companies still prefer to use open source software. <\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-27361","post","type-post","status-publish","format-standard","hentry","category-open-source-software"],"_links":{"self":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/posts\/27361"}],"collection":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/comments?post=27361"}],"version-history":[{"count":0,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/posts\/27361\/revisions"}],"wp:attachment":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/media?parent=27361"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/categories?post=27361"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/tags?post=27361"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}