The Register® — Biting the hand that feeds IT

Feeds

Red Hat heads security initiative

Government-backed

Ensure Ease of Recovery with Asigra’s Agentless Software

Red Hat is leading an initiative allowing software companies to brief users of a US government-backed security database on how far vulnerabilities affect their products.

The Linux vendor has asked that companies can now comment on security holes listed by the National Vulnerability Database (NVD), in order to provide deeper analysis and explanation of the impact problems might have on their products.

The NVD houses data on 19,200 vulnerabilities going back eight years, and is sponsored by the Department of Homeland Security's National Cyber Security Division. The database is managed by the National Institute of Standards and Technology.

Red Hat is understood to have approached Novell, Hewlett-Packard, IBM and Mandriva to support its initiative, but only Mandriva has so far taken advantage of the service.

Red Hat is reported to have acted in the wake of a recently reported error in Apache that allowed unauthorised access to memory. Unlike other Linux companies, Red Hat did not release a patch because its Linux distribution was not affected. However, that did not stop customers from contacting Red Hat for advice.

Red Hat said the new NVD service would allow for timely dissemination of security information, so customers could quickly take action if necessary.

Red Hat security response director Mark Cox said in a statement: "We can now provide official statements about vulnerabilities and their potential impact via a widely recognised mechanism, as well as enable the entire software industry to contribute." ®

Customer Success Testimonial: Recovery is Everything

More from The Register

SCO vs. IBM battle resumes over ownership of Unix
Zombie lawsuit back and wants to suck the brains out of Linux
Bjarne Again: Hallelujah for C++
Plus: Now officially OK to admit you never used STL algorithms
Interwebs taunt Sir Jony over Apple eye candy makeover
Hey Ive, Ive... add more unicorns, willya?
Apple: iOS7 dayglo Barbie makeover is UNFINISHED - report
Plus: You don't like the icons? Blame marketing
Red Hat to ditch MySQL for MariaDB in RHEL 7
So long, Oracle! Don't let the door hit you on the way out
Shy? Socially inadequate? Fiddling with your phone could help
App 'tells the brutal truth' about social inadequates' chatup lines
Java EE 7 melds HTML5 with enterprise apps
New release arrives with GlassFish, NetBeans support
 breaking news
'Office Facebook' firm Tibbr wants you to PAY for mobe-meetings app
Great idea. Punters won't cough for it though
 breaking news
The only Waze is Google: Ad giant tipped to gobble map app 'for $1.3bn'
Pac-Man-satnav-ish upstart in bidding war with Apple, Facebook
 breaking news
PM Cameron calls for modern, programmable computers! (We think)
IT education musings to G8 chiefs to mystify IT industry