Jump to content

Security bug

From Wikipedia, the free encyclopedia
This is an old revision of this page, as edited by Schmloof (talk | contribs) at 23:38, 4 July 2010 (WikiCleaner 0.99 - Repairing link to disambiguation page - You can help!). The present address (URL) is a permanent link to this revision, which may differ significantly from the current revision.

A security bug is a software bug that benefits someone other than intended beneficiaries in the intended ways.

Security bugs introduce security vulnerabilities by compromising one or more of:

Security bugs need not be identified, surfaced nor exploited to qualify as such. Some exploited ones, particularly viruses, have been known to wreak global damage at massive cost.

Causes

Security bugs, like all other software bugs, stem from root causes that can generally be traced to either absent or inadequate:

Taxonomy

Security bugs generally fall into a fairly small number of broad categories that include:

Mitigation

See Software Security Assurance.