|
Fortify Identifies Vulnerabilities in Open Source Software |
|
|
|
Source: LinuxLookup - Posted by Bill Keys
|
Fortify Software announced that Fortify’s Security Research Group has identified a new class of security vulnerabilities, known as cross–build injection. These vulnerabilities, which Fortify discovered through its work with the Java Open Review (JOR) project (http://opensource.fortify.com), allow a hacker to insert code into the target program while it is being constructed.
What do you think about Fortify releasing whitepapers detailing this new class of vulnerabilities. Are they opening the door open for attackers to exploit? I don't think, they are hoping that software developers will listen and prevent these attacks from happening.
Read this full article at LinuxLookup
Powered by AkoComment! |