Language Selection

English French German Italian Portuguese Spanish

Flaws could open systems to attack

Filed under
Security

Two serious security flaws in a technology widely used for network authentication could expose a swath of software products to hacker attack, experts have warned.

The flaws could allow an online intruder to crash or gain access to computers running Kerberos, a freely available authentication technology that was developed by the Massachusetts Institute of Technology.

MIT rates both flaws "critical," according to two advisories released Tuesday. The university also made available patches to fix the problems and stated that exploitation of the bugs by attackers "is believed to be difficult."

Several software makers have already released updates to their products to address the problem. Red Hat, Turbolinux and Gentoo have issued fixes for their Linux versions, for example. Sun Microsystems on Tuesday issued two alerts acknowledging that several versions of Solaris are vulnerable, but it does not have a patch available yet.

Because Kerberos is so widely used, more vendors are likely to publish security alerts, said Brian Grayek, chief technology officer at Preventsys, a vulnerability management company in Carlsbad, Calif. "I think you are going to see a floodgate of patches open," he said.

Microsoft also uses Kerberos, but a homegrown version that is not affected by the flaws.

Both bugs affect Kerberos 5 Release 1.4.1 as well as earlier versions, according to MIT.

Independent security-monitoring company Secunia rates the issues "highly critical," its second most serious rating. The French Security Incident Response Team, or FrSIRT, deems the bugs "critical," its highest ranking.

Preventsys' Grayek agreed that the vulnerabilities are serious but noted that crafting attacks is difficult. "It is going to take somebody with a great deal of knowledge to turn these vulnerabilities into exploits," he said.

This isn't the first flaw in Kerberos. In March, MIT warned of a "serious" bug in the telnet program supplied with Kerberos. Last August, a "critical" flaw was discovered and patched.

Earlier this month a vulnerability in another widely used software component exposed some of the same products to attack. That flaw affects the open-source "zlib" data compression technology. Using a specially crafted file, an attacker could take control over a computer or crash applications that use zlib.

Source.

More in Tux Machines

DebEX Barebone Distro Now Uses Linux Kernel 4.2, Based on Debian 8.1 and Xfce 4.12

After announcing the release of the DebEX GNOME and KDE Editions, Arne Exton had the great pleasure of informing us about the immediate availability for download of a new build of his DebEX Barebone distribution. Read more

Elementary OS: Freya 0.3.1 is Here!

After just a few months, we’re excited to announce a major upgrade for elementary OS Freya! This new version 0.3.1 closes about 200 reports and brings new features, tons of fixes, better hardware support, visual polish, and enhanced translations. We’re very proud to share some elementary OS download stats as well! So far, elementary OS has been downloaded an estimated 5 million times. Of those downloads, we’re seeing that almost 70% are coming from Windows and OS X. So, “Welcome and congratulations!” to the over 3 million new users of an open source operating system! Read more

Announcing dex, an Open Source OpenID Connect Identity Provider from CoreOS

Today we are pleased to announce a new CoreOS open source project called dex: a standards-based identity provider and authentication solution. Just about every project requires some sort of authentication and user-management. Applications need a way for users to log-in securely from a variety of platforms such as web, mobile, CLI tools and automated systems. Developers typically use a platform-dependent solution or, just as often, find existing solutions don't quite address their needs and so they resort to writing their own solution from scratch. Read more

Samsung rolls out a round, Tizen-based Gear S2 watch

Samsung debuted its gen 2 smartwatch: a round, 11.5mm thick “Gear S2″ device with a 1.2-inch 360×360 pixel AMOLED display. As expected, it runs Tizen. Samsung’s Tizen Linux-based Gear S2 smartwatch, which was recently teased at the Galaxy Note 5 and Edge S6+ launch, features a round watch-faced, up to three days battery life, and a rotating bezel to augment the touchscreen UI. A slightly thicker 3G model with up to two hours of life supports voice calls, according to a report from The Verge. Read more