Coverity Scan Discovers Vulnerabilities in the Android Code
The 2010 security report looks at more than 291 projects, with special focus on the Android 2.6.32 kernel
Since 2006, Coverity has worked with the U.S. Department of Homeland Security to identify software security vulnerabilities. In 2010, Coverity analyzed more than 61 million lines of open source code from more than 291 projects, including Android, Linux, Apache, Samba and PHP. According to the Coverity Scan 2010 Open Source Integrity Report, 45 percent of the identified vulnerabilities are considered "high-risk defects". The report also says that little has changed since 2008 in software development testing to help identify these security concerns and goes on to say, "It also demonstrates how easy it is to make these types of coding errors when the human factor comes into play."
This year's report takes an in-depth look at the Android 2.6.32 kernel and says that HTC Droid Incredible has about half the defects that would be expected for similar software of the same size, with about 1 defect per 1,000 lines of code, 359 of them in the currently shipping version of the HTC Droid Incredible. The report points out the fragmented accountability for Android software development, saying, "Android is based on Linux, which has thousands of contributors. Compound that with the Android developers from Google, the contributors to Android from the larger development community, and OEMs that supply components for specific configurations of Android to support different types of devices, and the lines of accountability are quickly blurred."
The entire report is free and available for download on the Coverity site: http://www.coverity.com/
Tag Cloud
News
-
FSF Outs the World Wide Web Consortium over DRM Proposal
Richard Stallman calls for the W3C to remain independent of vendor interests.
-
Debian 7.0 Debuts
The new release supports nine architectures, 73 human languages, and zero non-Free components.
-
Alpha Version of Fedora 19 Released
Fedora developers release the first alpha version of Fedora 19, known as Schrödinger’s Cat, for general testing. The final release is expected in July 2013.
-
ack 2.0 Released
ack is a grep-like, command-line tool that has been optimized for programmers to search large trees of source code.
-
SUSE Studio 1.3 Released
New features in SUSE Studio 1.3 include enhanced cloud integration, VM platform support, and lifecycle management.
-
Xen To Become Linux Foundation Collaborative Project
The Linux Foundation recently announced that the Xen Project is becoming a Linux Foundation Collaborative Project.
-
RunRev Releases Open Source Version of LiveCode
Open source version of LiveCode is now available for developing apps, games, and utilities for all major platforms.
-
OpenDaylight Project Formed
OpenDaylight is an open source software-defined networking project committed to furthering adoption of SDN and accelerating innovation in a vendor-neutral and open environment.
-
Gnome 3.8 Released
The new Gnome release includes privacy and sharing settings, allowing more user control over access to personal information.
-
Mozilla and Samsung Collaborate on New Browser Engine
Mozilla is collaborating with Samsung on a new web browser engine called Servo.

