Language Selection

English French German Italian Portuguese Spanish

Flaws could open systems to attack

Filed under
Security

Two serious security flaws in a technology widely used for network authentication could expose a swath of software products to hacker attack, experts have warned.

The flaws could allow an online intruder to crash or gain access to computers running Kerberos, a freely available authentication technology that was developed by the Massachusetts Institute of Technology.

MIT rates both flaws "critical," according to two advisories released Tuesday. The university also made available patches to fix the problems and stated that exploitation of the bugs by attackers "is believed to be difficult."

Several software makers have already released updates to their products to address the problem. Red Hat, Turbolinux and Gentoo have issued fixes for their Linux versions, for example. Sun Microsystems on Tuesday issued two alerts acknowledging that several versions of Solaris are vulnerable, but it does not have a patch available yet.

Because Kerberos is so widely used, more vendors are likely to publish security alerts, said Brian Grayek, chief technology officer at Preventsys, a vulnerability management company in Carlsbad, Calif. "I think you are going to see a floodgate of patches open," he said.

Microsoft also uses Kerberos, but a homegrown version that is not affected by the flaws.

Both bugs affect Kerberos 5 Release 1.4.1 as well as earlier versions, according to MIT.

Independent security-monitoring company Secunia rates the issues "highly critical," its second most serious rating. The French Security Incident Response Team, or FrSIRT, deems the bugs "critical," its highest ranking.

Preventsys' Grayek agreed that the vulnerabilities are serious but noted that crafting attacks is difficult. "It is going to take somebody with a great deal of knowledge to turn these vulnerabilities into exploits," he said.

This isn't the first flaw in Kerberos. In March, MIT warned of a "serious" bug in the telnet program supplied with Kerberos. Last August, a "critical" flaw was discovered and patched.

Earlier this month a vulnerability in another widely used software component exposed some of the same products to attack. That flaw affects the open-source "zlib" data compression technology. Using a specially crafted file, an attacker could take control over a computer or crash applications that use zlib.

Source.

More in Tux Machines

Photoshop competitor Krita is a true creative tool -- and it's free and open source

Open source has some of the greatest tools, which continues to prove that you don't have to lock-down the code behind guarded walls to make a better product. Some popular open source products that don't have any match in the closed source world include Firefox, Chromium, VLC, Blender, Android, one gem that is, surprisingly, less known but extremely powerful when it comes to creating a work of art. Read more

First peek at the next Ubuntu 15.04 nester line-up

Ubuntu 15.04 is here – almost. The first beta of Vivid Vervet has been delivered, and with it have come images of the penguin flock that nestles on this OS. I looked at Xubuntu, Kubuntu, Ubuntu GNOME and Ubuntu MATE but there’s also Lubuntu and the China-centric Ubuntu Kylin, which I didn’t test. These are beta releases and should be considered for testing purposes only, but the advantage of these early versions is that features have been frozen and you can get an early glimpse of what's coming for each of the popular flavours in the 15.04 foundation. From this point on, the only changes will be bug fixes. Read more

Review: Simplicity Linux 15.4 alpha

Overall I give it 2 Thumbs Up on speed and layout of OS. If you have a computer with low resources, then this is an OS for you to try. Read more

Eurostat continues to share and use open source

Eurostat, the statistical office of the European Communities, continues to release as open source its ICT solutions. To date, Eurostat has shared 102 solutions on the European Commission’s Joinup platform. The statistical office has been using and sharing open source for more than a decade. Already in 2004 Eurostat’s ICT policy stipulated to consider open source software for all new projects. Read more