Language Selection

English French German Italian Portuguese Spanish

Flaws could open systems to attack

Filed under
Security

Two serious security flaws in a technology widely used for network authentication could expose a swath of software products to hacker attack, experts have warned.

The flaws could allow an online intruder to crash or gain access to computers running Kerberos, a freely available authentication technology that was developed by the Massachusetts Institute of Technology.

MIT rates both flaws "critical," according to two advisories released Tuesday. The university also made available patches to fix the problems and stated that exploitation of the bugs by attackers "is believed to be difficult."

Several software makers have already released updates to their products to address the problem. Red Hat, Turbolinux and Gentoo have issued fixes for their Linux versions, for example. Sun Microsystems on Tuesday issued two alerts acknowledging that several versions of Solaris are vulnerable, but it does not have a patch available yet.

Because Kerberos is so widely used, more vendors are likely to publish security alerts, said Brian Grayek, chief technology officer at Preventsys, a vulnerability management company in Carlsbad, Calif. "I think you are going to see a floodgate of patches open," he said.

Microsoft also uses Kerberos, but a homegrown version that is not affected by the flaws.

Both bugs affect Kerberos 5 Release 1.4.1 as well as earlier versions, according to MIT.

Independent security-monitoring company Secunia rates the issues "highly critical," its second most serious rating. The French Security Incident Response Team, or FrSIRT, deems the bugs "critical," its highest ranking.

Preventsys' Grayek agreed that the vulnerabilities are serious but noted that crafting attacks is difficult. "It is going to take somebody with a great deal of knowledge to turn these vulnerabilities into exploits," he said.

This isn't the first flaw in Kerberos. In March, MIT warned of a "serious" bug in the telnet program supplied with Kerberos. Last August, a "critical" flaw was discovered and patched.

Earlier this month a vulnerability in another widely used software component exposed some of the same products to attack. That flaw affects the open-source "zlib" data compression technology. Using a specially crafted file, an attacker could take control over a computer or crash applications that use zlib.

Source.

More in Tux Machines

Open spec SBC dual boots Android and Ubuntu on hexa-core RK3399

T-Firefly is Kickstartering the first hacker SBC with Rockchip’s Cortex-A72/-A53 RK3399. The Firefly-RK3399 has up to 4GB DDR3, M.2, and USB 3.0 Type-C. T-Firefly, which offers Linux- and Android-ready open source boards like the Firefly-RK3288 and sandwich-style Firefly-RK3288 Reload, both of which are based on the quad-core, Cortex-A17 Rockchip RK3288, has advanced to a more powerful Rockchip SoC for its new open spec Firefly-RK3399. The hexa-core Rockchip RK3399 features two server-class Cortex-A72 cores clocked to up to 2.0GHz, as well as four Cortex-A53 at up to 1.42GHz. This appears to be the first RK3399 SBC and the first SBC to include Cortex-A72 cores. Read more

Leftovers: Software

  • Manuskript is a Promising Open-Source Scrivener Alternative
    Whether you plan to work on a book, a screenplay, or better structure your dissertation, you’ll probably see apps like Scrivener recommended. If you’re running Windows, macOS or even Android then you’re spoilt for choice, with various competing proprietary apps at varying price points readily available. On Linux the choices are somewhat limited.
  • Tor 0.2.9 Is Just Around the Corner As 0.2.8.10 Fixes Memory Leak in OpenSSL 1.1
    The past weekend brought us new stable and development builds of the Tor anonymity network project, versioned 0.2.8.10, as the most advanced version out there, and 0.2.9.6 RC (Release Candidate).
  • Pitivi 0.98 Linux Video Editor Adds Customizable Keyboard Shortcuts
    Version 0.98 of the GNOME-aligned GStreamer-powered Pitivi non-linear video editor was tagged today as the newest development milestone. The main feature addition of Pitivi 0.98 is now supporting customizable keyboard supports! Aside from finally supporting customizable keyboard shortcuts for this open-source video editor, a lot of warnings were fixed from GTK 3.22, and there has been a lot of other bug fixing. Bugs around Pitivi's timeline were primarily targeted by this release.
  • Phoronix Test Suite 6.8-Tana Officially Released
    Phoronix Test Suite 6.8.0 is now available as the latest version of our open-source, fully-automated, reproducible benchmarking software for Linux, BSD, Solaris, macOS, Windows, and other operating systems. Phoronix Test Suite 6.8 is the latest stable release now of our GPL-licensed benchmarking software updated on its regular quarterly release cadence. Phoronix Test Suite 6.8 development focused on a number of low-level improvements to particularly benefit Phoromatic and the Phodevi (Phoronix Device Interface) software/hardware library abstraction layer.
  • iPerf As Another Network Benchmark Is Now Available Via The Phoronix Test Suite
  • Chromium-Based Vivaldi 1.6 Browser Enters Development, Brings Tab Stack Renaming
    Vivaldi's Ruarí Ødegaard informs us about the availability of a new snapshot for the cross-platform, Chromium-based Vivaldi web browser, which promises to let users name tab stacks. Vivaldi Snapshot 1.6.682.3 marks the beginning of the development of Vivaldi 1.6, the next major version of the popular web browser, and it looks like it has been rebased on Chromium 55.0.2883.64. Besides fixing a bunch of regressions, the new development release implements an option under Settings -> Tabs -> Tab Features -> Tab stacking -> Allow Tab Stack Renaming, which lets you rename or name tab stacks.

today's howtos