The Register® — Biting the hand that feeds IT

Feeds

Minor bugs bite patch security checking tool

  • alert
  • print

Ants in your pants

Watch Now : Virtual Machine Movement with Hyper-V

A security researcher claims to have found a trio of coding bugs in Secunia's popular security inspection tool.

Secunia PSI, which provides a handy way to check if applications installed on a computer are up to date, has a bug in its interface which allows anything to be inserted, according to blogger Raul Romero.

Romero posted a screenshot of a (SFW) rear view of an amply proportioned lady in a tracksuit within the PSI interface to illustrate this point. Another bug allows cookies to be read while the third remains undisclosed at the time of writing.

Thomas Kristensen, chief security officer at Secunia, told The Register that Romero had failed to demonstrate any vulnerability with its technology.

"Based on the vague information he has posted there is no proof of a security issue," Kristensen said.

"However, assuming that one can insert images and scripts as part of the profile, then it would only be a bug and not a security issue because the user only can do this to himself."

He added that Secunia takes any claims about security issues in its technology seriously.

All three bugs - all of which appear to be small beer - are yet to be confirmed but do illustrate the point that even security applications are prone to coding errors from time to time. ®

Watch Now : Virtual Machine Movement with Hyper-V

Hands on with Hyper-V 3.0 and virtual machine movement

Our award-winning Regcasts have teamed up with training provider QA for the deepest of deep dives into Hyper-V, including a live demo.

Understand VM movement - just click to play, or go here for a bigger version.