Researchers Track Spread of Security Flaws in Software Libraries | eWeek

Researchers Track Spread of Security Flaws in Software Libraries

Researchers Track Spread of Security Flaws in Software Libraries
Written By
Robert Lemos
Robert Lemos
Jul 17, 2014
3 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

When security researchers publicly released details of the Heartbleed OpenSSL flaw in April, Websites and application vendors rushed to fix their software to eliminate the vulnerability.

In the end, some 200 products and Web services—ranging from top online services such as Netflix and Google to nearly a score of Oracle products and almost every version off Linux—were affected by the security bug.

The well-known incident highlights the trouble with security vulnerabilities in popular infrastructure software, frameworks and libraries, according to Kymberlee Price, director of ecosystem strategy at Synack, and Jake Kouns, chief information security officer for Risk Based Security.

The two security professionals will present their analysis of popular software components—including LibPNG, used by more than 130 popular software products, and FreeType, used in more than 30 applications—during the Black Hat Security Briefings August 2-7 in Las Vegas.

“The model we have been looking at initially has been more of a disease-spread model, where you have one infective agent, such as (a vulnerability in) OpenSSL, and you look at where that is spreading to,” Price told eWEEK. “The question for companies is, how many vaccines will you need to take every year … and what is the cadence of those patches?”

Companies should take stock of all the software libraries that they use to develop their products or internal software systems and track the applications that rely on those components. A vulnerability can be amplified if it affects a fundamental third-party library and thus impacts every product that utilizes that software. To prevent their applications from inadvertently being weakened by unknown flaws, developers should track their usage of third-party software and monitor the libraries for vulnerabilities.

“You need that evaluation prior to selecting a library,” Kouns told eWEEK. “There is a big difference between a library that is well maintained—sure, it might have vulnerabilities, but the team, whether open or closed, is on top of it—versus a library that is end of life or is written by a 13-year-old.”

While third-party software frameworks and libraries have become a major concern to security professionals, many developers are not yet aware of the problem. Only 37 percent of developers, architects and managers, actively monitor their software components for vulnerability disclosures, according to a survey of nearly 3,400 people conducted by software management firm Sonatype in April.

Even if they were aware of a vulnerability in a library which they depended on, about 60 percent would have trouble tracking down the affected software, because they do not maintain an inventory of open-source components, according to the firm’s 2014 Open Source Development Survey.

To use third-party software securely, companies should both track the vulnerabilities in the libraries and frameworks that they use. They should also keep an inventory of the software components that they use in their production applications, said Kouns of Risk Based Security.

“We continue to advise people that you want to work with vendors—whether closed or open or libraries or not—that get fixes out quickly,” he said. “If you care about security, you want to use those products.”

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.