Commercial software companies and open source community reaction to disclosed vulnerabilities: Case of Windows Server 2008 and Linux patching
Mhamed Zineddine, Chakib Alaoui, Nourddin Saidou · 2017
Open source and closed software security has been debated for decades, vulnerabilities reported for both types of software has been under scrutiny for years. In this study, a descriptive and correlation study for two selected systems is conducted using SPSS 19. The results show that the severity score average of Linux kernel vulnerabilities is lower by %30 than the severity score average of vulnerabilities of windows server 2008, and the time required to patch published vulnerabilities is relatively faster for commercial than open source software. However, a positive correlation between Windows server 2008's variables reveal the irony that severity scores and patch delays are moving in the same direction. The contribution of this article is to shed light on the perception about the security divide between open source and closed software under study that is, although the commercial companies respond faster, however, not according to the severity of vulnerabilities disclosed.