Secunia: 28 Percent of Software Unpatched

By Ed Oswald | Published May 18, 2007, 1:07 PM

Secunia says that over one-quarter of applications on users' PCs lack the necessary patches released by software vendors to address critical issues.

Media players seem to be the most commonly vulnerable, with over 33 percent of all Quicktime, and 27 percent of Winamp installations missing important security updates. Browsers do better, with a little over five percent of Firefox, 5.4 percent of IE7, 9.6 percent of IE6, and nearly 12 percent of all Opera 9 installs missing security updates.

The data was culled through anonymous data provided by Secunia's Software Inspector, an online tool that scans a user's computer to ensure applications have the latest security updates for installed applications. The program has been used over 350,000 times.

Secunia said that it believes the percentages of unpatched Microsoft applications are relatively low because of the knowledge of its regular Patch Tuesday program. But it appears with other applications that computer users wait an extended period of time to patch problems.

"This constitutes a significant problem because many of those applications, like WinAMP and Quicktime, are readily used whenever users encounter media files of various kinds," Secunia's Jakob Balle said, noting it would only take one bad QuickTime video to cause trouble with a lot of people.

Balle noted that similar vulnerabilities are also a serious issue in the corporate sector. "Corporations have much more to lose than just their credit card details; there's client lists, design blueprints, employee information, and more at stake," he said.

Comments

Agreed that it's probably much higher. Average computer users probably don't know about secunias scanner tool, and they probably don't care or "know" that many of the software on their computers has updates available. Wouldn't be surprised if the number was actually higher than 50 percent.

Score: 0

|

How on Earth can they pull a number like 28 percent? I don't buy it. Almost any number like that is speculative at best.

Score: 0

|

Agreed. The number must be much higher than that.

Score: 0

|

They have a software scanner that is run against people's machines.

I run it myself for side jobs and I tend to agree with it. It's amazing how many people are on very old versions of quicktime/itunes, which is of course very vulnerable.

Score: 0

|

Can Linux do BitLocker better than Windows 7?

Betanews kicks off a new series with a look at how the Linux operating system's FDE stacks up against BitLocker, the Windows feature that today commands a $120 premium.

Firefox 3.5: The need for speed

This has been the big payoff week for Mozilla's developers, who worked overtime to squeeze out the last drop of performance from their new JavaScript engine.

'GeoHot' gets a shower, cleans up nice, reveals new iPhone 3G S jailbreak

Either puberty has been very kind to the author of the new 'Purple Ra1n' jailbreak tool, or George Hotz may also have some adequate Photoshop skills.

What's Next: Obama gives 'Einstein' the go-ahead, while China gives 'Green Dam' a thumbs-down

Plus: If you put up a Web site and name it after you and you're a federal judge, you might not want a bunch of weird nudity hanging around on it.

Why would Windows 7 customers spend $120 more for BitLocker?

For pre-orders from now until July 11, Microsoft is offering the Windows 7 Professional SKU for a very steep discount. So why invest in Ultimate?

Geeks vs. journalists: A tale of two worldviews

Recovery with Angela Gunn Why geeks think most mainstream journalism is flaky, and why the mainstream thinks geeks are trying to kill them. (They're both right.)

Fire in downtown Seattle data center knocks out businesses, online services

Small fire has global impact with payment centers, city services down.

Hybrid satellite cell phones aren't far off

The first satellite in Terrestar's hybrid cellular/satellite phone network has been launched.

SMS could be a critical iPhone vulnerability, says white-hat hacker

Mac hacker Charlie Miller knows how to get into your iPhone.

Will Oracle's Java-based Fusion middleware 'fuse' with Java?

Now that Oracle has acquired Sun Microsystems, Java developers and supporters are wondering when Oracle will formally welcome Java into the family.

All together now: iPhone and Palm Pre, likely to both grace O2's UK portfolio

European wireless network operator O2 has reportedly reached a deal to exclusively carry the Palm Pre in the UK. O2,...

Vista's dead: Microsoft kills an OS and no one cares

Carmi Levy: Wide Angle Zoom Can you kill an operating system? Microsoft is about to find out.

Kantaris Media Player 0.5.7

July 3 - 5:34 PM ET

Wine 1.1.25

July 3 - 5:30 PM ET

ChrisTV Online! Free 4.00

July 3 - 5:22 PM ET

glu 1.0.19 RC1

July 3 - 5:11 PM ET

Website-Watcher 5.1.0 Beta 10

July 3 - 1:20 PM ET