Language Selection

English French German Italian Portuguese Spanish

Flaws could open systems to attack

Filed under
Security

Two serious security flaws in a technology widely used for network authentication could expose a swath of software products to hacker attack, experts have warned.

The flaws could allow an online intruder to crash or gain access to computers running Kerberos, a freely available authentication technology that was developed by the Massachusetts Institute of Technology.

MIT rates both flaws "critical," according to two advisories released Tuesday. The university also made available patches to fix the problems and stated that exploitation of the bugs by attackers "is believed to be difficult."

Several software makers have already released updates to their products to address the problem. Red Hat, Turbolinux and Gentoo have issued fixes for their Linux versions, for example. Sun Microsystems on Tuesday issued two alerts acknowledging that several versions of Solaris are vulnerable, but it does not have a patch available yet.

Because Kerberos is so widely used, more vendors are likely to publish security alerts, said Brian Grayek, chief technology officer at Preventsys, a vulnerability management company in Carlsbad, Calif. "I think you are going to see a floodgate of patches open," he said.

Microsoft also uses Kerberos, but a homegrown version that is not affected by the flaws.

Both bugs affect Kerberos 5 Release 1.4.1 as well as earlier versions, according to MIT.

Independent security-monitoring company Secunia rates the issues "highly critical," its second most serious rating. The French Security Incident Response Team, or FrSIRT, deems the bugs "critical," its highest ranking.

Preventsys' Grayek agreed that the vulnerabilities are serious but noted that crafting attacks is difficult. "It is going to take somebody with a great deal of knowledge to turn these vulnerabilities into exploits," he said.

This isn't the first flaw in Kerberos. In March, MIT warned of a "serious" bug in the telnet program supplied with Kerberos. Last August, a "critical" flaw was discovered and patched.

Earlier this month a vulnerability in another widely used software component exposed some of the same products to attack. That flaw affects the open-source "zlib" data compression technology. Using a specially crafted file, an attacker could take control over a computer or crash applications that use zlib.

Source.

More in Tux Machines

MX Tools - A year later, the toolbox got better

Roughly fourteen full phases of the moon ago, I wrote an article on MX Tools, a unique and useful bunch of dedicated utilities packaged with the MX Linux distribution. This toolbox offered the ordinary (or new) MX Linux user a chance to perform some common configuration tasks with easy and elegance. In general, MX-16 was a great player, and the recent MX-17 is even better - and at a first glance, so is the new version of MX Tools bundled with the system. Good stuff. So I set about testing, to see what has changed, and in what way this set of utilities has improved, if at all. But I'm positive. Let us commence. [...] MX Tools turned out to be a predictable gem, just as I'd expected. Well, I'm cheating, because I wrote this article after some rather thorough testing. But then, if you look across the wider spectrum of Linux home distributions, there aren't that many unique players with distinctive features. Quite often, it's the rehash of old and familiar with some extra color, polish and rebranding. MX Linux goes the extra mile (or kilometer, if you will) in making the newbie experience meaningfully different. Future improvements could potentially include an interactive walkthrough - so users will be actively prompted and helped along in their tasks. Then of course, there's the matter of visual appearance, in the UI itself. But in general, MX Tools TNG is better than we had before. More elegant, more streamlined, better looking, and most importantly, more practical. This is a good and useful toolbox, and it makes a solid distro even more appealing. Well worth testing. So do it. And take care. Read more

The story of Gentoo management

I have recently made a tabular summary of (probably) all Council members and Trustees in the history of Gentoo. I think that this table provides a very succinct way of expressing the changes within management of Gentoo. While it can’t express the complete history of Gentoo, it can serve as a useful tool of reference. What questions can it answer? For example, it provides an easy way to see how many terms individuals have served, or how long Trustee terms were. You can clearly see who served both on the Council and on the Board and when those two bodies had common members. Most notably, it collects a fair amount of hard-to-find data in a single table. Read more

Success for net neutrality, success for free software

We've had great success with the United States Senate voting in support of net neutrality! Congratulations and thank you to everyone in the US for contacting your congresspeople, and all of you who helped spread the word. However, it's not over yet. Here are more actions you can take if you're in the United States. Now that the (CRA) has passed the Senate, it moves to the House of Representatives. Just as we asked you to call your senators, now it's time to call your House representatives. Find their contact info here and use the script below to ask them to support the reinstatement of net neutrality protections. The timing hasn't been set for future votes and hearings yet, but that's no reason to wait: make sure your representatives know how you feel. Read more Also: GNU Spotlight with Mike Gerwitz: 18 new GNU releases!

today's leftovers

  • 10 Reasons Why Desktop Linux Isn’t Mainstream – For The Record
    10 Reasons Why Desktop Linux Isn’t Mainstream. Yeah, the title is totally link-bait. However, it’s worth noting that I actually deliver what the title describes and then some. Linux is awesome, but sadly, most people haven’t heard of it. Here’s why.
  • Linux Works For You
    Linux allows YOUR computer to work for you, not against you. Wearing this shirt/hoodie demonstrates to all who see it that you are not a slave to your PC. You are in control and Linux is the reason for this.
  • Robin "Roblimo" Miller
    The Linux Journal mourns the passing of Robin Miller, a longtime presence in our community.
  •  
  • Pidgin / Libpurple SkypeWeb Plugin Sees New Stable Release
    SkypeWeb is a plugin that allows using Skype in Pidgin / libpurple chat clients. The plugin can be used to send instant messages and participate in group chats, but it does not yet support voice / video calling.
  • Feral's GameMode May Soon Have Soft Real-Time Capabilities
    Feral Interactive's Linux system tuning daemon, GameMode since being introduced earlier this year has primarily offered the ability to easily change the CPU scaling governor when gaming but not much more. Though a new feature is now in the works for GameMode.
  • Mini DebConf Hamburg
    Last week I attended the MiniDebConfHamburg. I worked on new releases of dracut and rinse. Dracut is an initramfs-tools replacement which now supports early microcode loading. Rinse is a tool similar to debootstrap for rpm distributions, which now can create Fedora 28 environments aka chroots.
  • Android and Automotive Grade Linux battle, as car becomes a data center
    Volvo’s decision to pick Intel’s Atom automotive system-on-chip (SoC) to run in-vehicle infotainment (IVI) for its new XC40 SUV highlights the intensifying competition among chipmakers in this fast growing sphere. The decision to base the system on Android also illuminates the evolving operating system scene for cars, with Linux the primary alternative in its AGL (Automotive Grade Linux) variant. However, given the complementary strengths of Android and Linux, it looks more likely that both will be deployed by many automobile makers in hybrid packages, so that they can take advantage of Android’s huge app ecosystem, encouraging plenty of third party enhancements, as well as harnessing the independence and enterprise scale of Linux. As cars become mini-data centers or edge compute…
  • Vending machine boardset works with UP or UP Squared boards
    Aaeon’s “AIOT-MSSP01” is a vending machine boardset powered by a PIC32 MCU that’s optimized to work with the UP or UP Squared SBCs. It offers vending-friendly I/O like MDB, EXE, and DEX, as well as motor controllers and 6x USB ports. The AIOT-MSSP01 is an industrial-grade vending machine controller (VMC) solution designed to run 24/7 “without a glitch,” says Aaeon. The boardset is optimized for use with the UP or UP Squared SBCs, but works with standard PCs and “most computer boards on the market.” There’s no mention of OS support for the connected computer, but the UP SBCs support Linux, Android, and Windows.