<?xml version="1.0" encoding="utf-8"?><!-- generator="WordPress/2.9.2" -->
<rss version="0.92">
<channel>
	<title>Software bugs</title>
	<link>http://buglinks.puzzling.org</link>
	<description>Links to bug reporting techniques, tips and tools</description>
	<lastBuildDate>Sun, 29 Jun 2008 00:28:13 +0000</lastBuildDate>
	<docs>http://backend.userland.com/rss092</docs>
	<language>en</language>
	
	<item>
		<title>Adobe Reader might be patched, but it&#8217;s hard to tell</title>
		<description><![CDATA[Michael Horowitz  is annoyed that users cannot easily tell if they have a major Adobe Reader security patch installed. Both the unpatched and patched versions report themselves as version 8.1.2. He reports various ways to check on different versions of Microsoft Windows, but even security software is having trouble checking correctly.
Upshot for vendors: a [...]]]></description>
		<link>http://buglinks.puzzling.org/archives/2008/06/adobe-reader/</link>
			</item>
	<item>
		<title>Ubuntu and bugs</title>
		<description><![CDATA[Mark Shuttleworth describes the particular problems operating system distributions have with bugs: they are a collection point for bugs in many products and have a responsibility to their users to get the bugs to the places where they will be fixed:
Our primary goals should be to ensure that fixes we produce, and information we generate [...]]]></description>
		<link>http://buglinks.puzzling.org/archives/2008/06/ubuntu-and-bugs/</link>
			</item>
	<item>
		<title>When a security report is treated as a feature request</title>
		<description><![CDATA[Dave Goldsmith has some experience trying to report a security vulnerability to a company that does not have a security-specific process:

I reply:
Can you give me some guidance on your response guidelines to security vulnerabilities? Is there a timeframe that you try and have vulnerabilities fixed by?
They reply:

    Hi David,
    [...]]]></description>
		<link>http://buglinks.puzzling.org/archives/2008/06/when-a-security-report-is-treated-as-a-feature-request/</link>
			</item>
	<item>
		<title>Timing 0-day announcements for major releases</title>
		<description><![CDATA[The bMighty Blog describes how a bug in Firefox which was present in the 2.x series and was in the 3.0 released version has created some controversy: did the security researcher know about the bug earlier and choose the timing of the announcement purely for the publicity?
In other words, this is an issue that could [...]]]></description>
		<link>http://buglinks.puzzling.org/archives/2008/06/timing-0-day-announcements-for-major-releases/</link>
			</item>
	<item>
		<title>Citect takes five months to fix security hole</title>
		<description><![CDATA[Citect was notified of a buffer overflow bug in their remote plant management systems in January 2008 and has only just released a fix, writes TechNewsWorld:
&#8220;The problem is a classic example of buffer overflow from the &#8217;90s,&#8221; Core Security CTO Ivan Arce told TechNewsWorld. &#8220;It&#8217;s not a very sophisticated thing, [which] makes it surprising.&#8221;
&#8230;
The flaw [...]]]></description>
		<link>http://buglinks.puzzling.org/archives/2008/06/citect-takes-five-months-to-fix-security-hole/</link>
			</item>
	<item>
		<title>Triage best practices for web development</title>
		<description><![CDATA[In Kate Rhodes&#8217;s Best Practices for Web Developers, she addresses best practices for triage:
&#8230;lets be honest with ourselves. We&#8217;re actually ok with some things going &#8220;boom&#8221;. If we weren&#8217;t we&#8217;d be working for NASA. Every other development house I know of regularly releases software with bugs in it. As long as nothing too important breaks [...]]]></description>
		<link>http://buglinks.puzzling.org/archives/2008/06/triage-best-practices-for-web-development/</link>
			</item>
	<item>
		<title>Reporting high impact bugs</title>
		<description><![CDATA[Marie Hagman writes a Bug Reporting Best Practices guide with a focus on reporting bugs that are likely to be fixed:
Bugs that less likely to be fixed:
It would be great to fix every bug in the product, but it’s also great to ship J. In prioritizing which issues to fix, here are the some factors [...]]]></description>
		<link>http://buglinks.puzzling.org/archives/2008/06/reporting-high-impact-bugs/</link>
			</item>
	<item>
		<title>Coverity audit finds Open Source software has fewer bugs than in 2006</title>
		<description><![CDATA[The Register reports:
The quality of open source code has improved over the last two years, according to an audit sponsored by the US Department of Homeland Security.
The security and quality of more than 250 open source projects &#8211; including Apache, Linux, Firefox and PHP &#8211; was assessed using code analysis tools from Coverity as part [...]]]></description>
		<link>http://buglinks.puzzling.org/archives/2008/06/coverity-audit-finds-open-source-software-has-fewer-bugs-than-in-2006/</link>
			</item>
	<item>
		<title>Ubuntu global bug jam</title>
		<description><![CDATA[Ubuntu is having a bug jam between 8th and 10th August 2008. As The Fridge says:

So, what is the Ubuntu Global Bug Jam? Put simply, it is a world-wide online and face-to-face event to get people together to fix Ubuntu bugs &#8211; we want to get as many people online fixing bugs, having a great [...]]]></description>
		<link>http://buglinks.puzzling.org/archives/2008/06/ubuntu-global-bug-jam/</link>
			</item>
	<item>
		<title>Bug causes financial risk to be underestimated</title>
		<description><![CDATA[ZDNet reports that the credit rating agency Moody&#8217;s incorrect rated a risky investment as having its top rating as an investment:
Computerworld UK quotes Ralph Silva, senior analyst at financial services advisory firm Tower Group, regarding rating agencies’ lackadaisical attitude toward technology management:
Ratings agencies never put sufficient emphasis on their technology resources,” he said. In spite [...]]]></description>
		<link>http://buglinks.puzzling.org/archives/2008/06/bug-causes-financial-risk-to-be-underestimated/</link>
			</item>
</channel>
</rss>
