Language Selection

English French German Italian Portuguese Spanish

Flaws could open systems to attack

Filed under
Security

Two serious security flaws in a technology widely used for network authentication could expose a swath of software products to hacker attack, experts have warned.

The flaws could allow an online intruder to crash or gain access to computers running Kerberos, a freely available authentication technology that was developed by the Massachusetts Institute of Technology.

MIT rates both flaws "critical," according to two advisories released Tuesday. The university also made available patches to fix the problems and stated that exploitation of the bugs by attackers "is believed to be difficult."

Several software makers have already released updates to their products to address the problem. Red Hat, Turbolinux and Gentoo have issued fixes for their Linux versions, for example. Sun Microsystems on Tuesday issued two alerts acknowledging that several versions of Solaris are vulnerable, but it does not have a patch available yet.

Because Kerberos is so widely used, more vendors are likely to publish security alerts, said Brian Grayek, chief technology officer at Preventsys, a vulnerability management company in Carlsbad, Calif. "I think you are going to see a floodgate of patches open," he said.

Microsoft also uses Kerberos, but a homegrown version that is not affected by the flaws.

Both bugs affect Kerberos 5 Release 1.4.1 as well as earlier versions, according to MIT.

Independent security-monitoring company Secunia rates the issues "highly critical," its second most serious rating. The French Security Incident Response Team, or FrSIRT, deems the bugs "critical," its highest ranking.

Preventsys' Grayek agreed that the vulnerabilities are serious but noted that crafting attacks is difficult. "It is going to take somebody with a great deal of knowledge to turn these vulnerabilities into exploits," he said.

This isn't the first flaw in Kerberos. In March, MIT warned of a "serious" bug in the telnet program supplied with Kerberos. Last August, a "critical" flaw was discovered and patched.

Earlier this month a vulnerability in another widely used software component exposed some of the same products to attack. That flaw affects the open-source "zlib" data compression technology. Using a specially crafted file, an attacker could take control over a computer or crash applications that use zlib.

Source.

More in Tux Machines

Leftovers: Gaming

Phoronix on Graphics

  • VLC Now Has Zero-Copy Support For GStreamer Video Decoding
    It was just last week we got to write about VLC 3.0 features and early planning for VLC 4.0 while this weekend in Git there is another feature to add to the list. The latest VLC development code now supports zero-copy GStreamer video decoding. With the zero-copy comes increased efficiency and performance.
  • NVIDIA GeForce GT 710: Trying NVIDIA's Newest Sub-$50 GPU On Linux
    The GeForce GT 710 is a cut-down version of the Kepler GK208, the already low-end core used by the lines of the GT 720 and GT 730 graphics cards as well as the mobile GT 720M/730M/735M/740M graphics processors. This really isn't a graphics card for gamers or anyone needing any serious GPU performance but rather as an upgrade for an entry-level system, someone just wanting to upgrade from their integrated graphics, and other minimally-demanding use-cases.
  • Mesa 11.2 Is Set For Branching In Just Two Weeks, Release In Just Over One Month
    The race is on to see if any of the Mesa/Gallium3D hardware drivers (or core Mesa itself) will reach any new version levels for Mesa 11.2.
  • AMD Is Looking At A Interoperability Interface For OpenCL Outside Of Mesa
    AMD's Marek Olšák has begun exploring an interoperability interface for OpenGL within Mesa and having a non-Mesa OpenCL implementation (not Clover OpenCL Gallium3D). Likely as part of their HSA work and hopefully in providing better AMD open-source OpenCL support aside from the (currently limited) Gallium3D Clover state tracker, Marek is trying to hash out an interface for allowing interoperability with "MesaGL" and a non-Mesa OpenCL driver.

FreeBSD 10.3 Now In Beta

FreeBSD developers have released today their first official development media for the upcoming FreeBSD 10.3. FreeBSD 10.3 Beta 1 is now available from their FTP server. Read more

today's leftovers