Language Selection

English French German Italian Portuguese Spanish

Flaws could open systems to attack

Filed under
Security

Two serious security flaws in a technology widely used for network authentication could expose a swath of software products to hacker attack, experts have warned.

The flaws could allow an online intruder to crash or gain access to computers running Kerberos, a freely available authentication technology that was developed by the Massachusetts Institute of Technology.

MIT rates both flaws "critical," according to two advisories released Tuesday. The university also made available patches to fix the problems and stated that exploitation of the bugs by attackers "is believed to be difficult."

Several software makers have already released updates to their products to address the problem. Red Hat, Turbolinux and Gentoo have issued fixes for their Linux versions, for example. Sun Microsystems on Tuesday issued two alerts acknowledging that several versions of Solaris are vulnerable, but it does not have a patch available yet.

Because Kerberos is so widely used, more vendors are likely to publish security alerts, said Brian Grayek, chief technology officer at Preventsys, a vulnerability management company in Carlsbad, Calif. "I think you are going to see a floodgate of patches open," he said.

Microsoft also uses Kerberos, but a homegrown version that is not affected by the flaws.

Both bugs affect Kerberos 5 Release 1.4.1 as well as earlier versions, according to MIT.

Independent security-monitoring company Secunia rates the issues "highly critical," its second most serious rating. The French Security Incident Response Team, or FrSIRT, deems the bugs "critical," its highest ranking.

Preventsys' Grayek agreed that the vulnerabilities are serious but noted that crafting attacks is difficult. "It is going to take somebody with a great deal of knowledge to turn these vulnerabilities into exploits," he said.

This isn't the first flaw in Kerberos. In March, MIT warned of a "serious" bug in the telnet program supplied with Kerberos. Last August, a "critical" flaw was discovered and patched.

Earlier this month a vulnerability in another widely used software component exposed some of the same products to attack. That flaw affects the open-source "zlib" data compression technology. Using a specially crafted file, an attacker could take control over a computer or crash applications that use zlib.

Source.

More in Tux Machines

The state of Linux gaming in the SteamOS era

For decades after Linux's early '90s debut, even the hardest of hardcore boosters for the open source operating system had to admit that it couldn't really compete in one important area of software: gaming. "Back in around 2010 you only had two choices for gaming on Linux," Che Dean, editor of Linux gaming news site Rootgamer recalls. "Play the few open source titles, Super Tux Kart and so on, or use WINE to play your Windows titles." Read more

Dutch share code and concepts of base registry

The Dutch government has made available as open source a catalogue of data and concepts used in the country’s ‘System of Basic Registrations’. The aim is to provide users and suppliers a comprehensive view of the system, and to make it available for reuse. Read more

​Canonical and Juniper team up on carrier-grade OpenStack SDN

Everyone loves clouds these days. But telecomm companies are understandably cautious about entrusting their technology to the cloud. Wouldn't you be if a failure mean dropping phone or data services to millions of customers? Still, Juniper Networks and Canonical, Ubuntu Linux's parent company are certain they can devise a carrier-grade OpenStack cloud for virtualizing core networks and network functions. Read more

Ubuntu Kylin 15.04 Makes It Easier for Windows Users to Adapt to the Unity Interface

The Ubuntu Kylin 15.04 Beta 1 (Vivid Vervet) operating system has also been released alongside the Kubuntu, Xubuntu, Lubuntu, Ubuntu GNOME, and Ubuntu MATE distributions, bringing a wide range of improvements, numerous updated components, as well as the usual bug fixes. We took the distribution for a test drive and created a nice screenshot tour for all users of the Chinese Ubuntu community. Read more