Subject: who will contact Coverity?
To: NetBSD security list <tech-security@netbsd.org>
From: William Allen Simpson <wsimpson@greendragon.com>
List: tech-security
Date: 01/19/2005 16:16:35
I was just talking to Perry Metzger the other day about code review,
and he mentioned trying to get some free automated tools.
With all the current news this week about the Linux code review,
http://www.coverity.com/datasheets/linux_report.pdf
and the Darwin code review,
http://www.immunitysec.com/downloads/nukido.pdf
maybe its time for some other BSDs?
Note that the immunitysec folks held on to their review for 6 months,
according to
http://news.com.com/Darwin+flaws+survive+in+Apples+Mac+OS+X/2100-1002_3-5540955.html?tag=macintouch)
<http://dw.com.com/redir?destUrl=http%3A%2F%2Fwww.immunitysec.com%2Fresources-advisories.shtml&siteId=3&oId=2100-1002-5540955&ontId=1009&lop=nl.ex>
Not very nice of them.
Anyway, the last paragraph of the Linux "white paper" says:
Coverity offers free code audits analogous to what is contained in
this report. If you are interested, please email sales@coverity.com
or please visit www.coverity.com.
--
William Allen Simpson
Key fingerprint = 17 40 5E 67 15 6F 31 26 DD 0D B9 9B 6A 15 2C 32