ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


Security threats Toolkit

Open-source flaw database opens its doors

Munir Kotadia ZDNet.co.uk

Published: 02 Apr 2004 14:00 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The Open Source Vulnerability Database (OSVDB) has launched a free Web site that catalogues security flaws in Internet-related software. It will, say its creators, promote more open collaboration between companies and individuals "and reduce expenses inherent with the development and maintenance of in-house vulnerability databases".

There are various specialist mailing lists that inform administrators and developers about newly discovered security vulnerabilities, but the OSVDB, which was launched in 2002, claims to be the first site to aggregate all this content onto a single searchable resource and make it freely available on the Web.

An OSVDB spokesperson said in a statement that the number of computer security vulnerabilities have increased more than 2,000 percent since 1995: "Tracking these vulnerabilities and their cures is critical for those who protect networked systems against accidental misuse and deliberate attack, from home users and small businesses to globe-spanning enterprises," he said.

Richard Starnes, director of incident response at Cable & Wireless, welcomed the resource because of the help it could offer to administrators keep track of an increasing number of online threats: "Administrators have to cover more than a dozen Web sites and mailing lists and it is getting to the point where even medium sized companies are having to look at hiring an intelligence officer to keep track of the latest vulnerabilities," he said.

In the same year that the OSVDB was created, antivirus company Symantec acquired SecurityFocus, which publishes the BugTraq mailing list that provides a similar service to its subscribers and opens the information to all Web users after a few days.

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
88 out of 222 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:







Sentry Posts Blog

Nasa and the virus

Yesterday the BBC ran a story about a computer virus making it into orbit, which I read with incredulity. OK, it's a nice silly season story on the surface, but what really got me was... More

3 comments

Customer data found on eBay server hig...

The recent news about customer details being retrieved from a server sold on eBay is yet another story about the sorry state of information security in the electronic age (see: http://news.zdnet.co.uk/...m).... More

Post a comment

Does it matter if you are an aardvark...

In spam terms, apparently it does. According to Cambridge University security expert Richard Clayton, if your email address is aardvark at animal.net, you are more likely to receive... More

1 comment