Source Link


Auditing open source software

Google encourages its employees to contribute back to the open source community, and there is no exception in Google’s Security Team. Let’s look at some interesting open source vulnerabilities that were located and fixed by members of Google’s Security team. It is interesting to classify and aggregate the code flaws leading to the vulnerabilities, to see if any particular type of flaw is more prevalent.

  1. JDK. In May 2007, I released details on an interesting bug in the ICC profile parser in Sun’s JDK. The bug is particularly interesting

via Google Blogs...

0 comments ↓

There are no comments yet...Kick things off by filling out the form below.

Leave a Comment