oss-sec mailing list archives
Re: Estimate for the total number of exploitable bugs in large linux distro?
From: Alan Coopersmith <alan.coopersmith () oracle com>
Date: Fri, 14 Jul 2017 07:58:37 -0700
On 07/14/17 02:45 AM, Steven Miano wrote:
Something like this? https://www.cvedetails.com/vendor/51/Ubuntu.html https://www.cvedetails.com/vendor/7838/Red-Hat.html https://www.cvedetails.com/vendor/26/Microsoft.html
Those are known vulnerabilities, with varying degrees of exploitability, and varying exploit conditions and sometimes differing views on where to draw the line on what is one issue or multiple issues. Some of them can be remotely exploited, some require a local user to take action. Some give access to those who had none, some give higher privs to those who had some, and some don't change your access levels at all. Of course, they don't count all the ones that haven't been publicly disclosed - either because they are unknown or only known to certain people. And when you start comparing numbers with Linux distros things get even messier - if you include the count of every issue in every package in their package repositories then you are including a far larger set of software than if you just count what's in others OS - but that doesn't mean they are more or less secure, just that they have more or less software available for easy installation. For a far more complete answer of why vulnerability counting is messy, hard, and just plain sucks, you can turn to the experts: https://media.blackhat.com/us-13/US-13-Martin-Buying-Into-The-Bias-Why-Vulnerability-Statistics-Suck-WP.pdf https://media.blackhat.com/us-13/US-13-Martin-Buying-Into-The-Bias-Why-Vulnerability-Statistics-Suck-Slides.pdf -- -Alan Coopersmith- alan.coopersmith () oracle com Oracle Solaris Engineering - https://blogs.oracle.com/alanc
Current thread:
- Estimate for the total number of exploitable bugs in large linux distro? Georgi Guninski (Jul 14)
- Re: Estimate for the total number of exploitable bugs in large linux distro? Greg KH (Jul 14)
- Re: Estimate for the total number of exploitable bugs in large linux distro? Steven Miano (Jul 14)
- Re: Estimate for the total number of exploitable bugs in large linux distro? Alan Coopersmith (Jul 14)
- Re: Estimate for the total number of exploitable bugs in large linux distro? Hanno Böck (Jul 14)
- Re: Estimate for the total number of exploitable bugs in large linux distro? Steve Grubb (Jul 14)
- Re: Estimate for the total number of exploitable bugs in large linux distro? Santiago Torres (Jul 14)
- Re: Estimate for the total number of exploitable bugs in large linux distro? Kurt Seifried (Jul 14)
- Re: Estimate for the total number of exploitable bugs in large linux distro? Javantea (Jul 14)
- Re: Estimate for the total number of exploitable bugs in large linux distro? Kristian Fiskerstrand (Jul 14)