Language Selection

English French German Italian Portuguese Spanish

Flaws could open systems to attack

Filed under
Security

Two serious security flaws in a technology widely used for network authentication could expose a swath of software products to hacker attack, experts have warned.

The flaws could allow an online intruder to crash or gain access to computers running Kerberos, a freely available authentication technology that was developed by the Massachusetts Institute of Technology.

MIT rates both flaws "critical," according to two advisories released Tuesday. The university also made available patches to fix the problems and stated that exploitation of the bugs by attackers "is believed to be difficult."

Several software makers have already released updates to their products to address the problem. Red Hat, Turbolinux and Gentoo have issued fixes for their Linux versions, for example. Sun Microsystems on Tuesday issued two alerts acknowledging that several versions of Solaris are vulnerable, but it does not have a patch available yet.

Because Kerberos is so widely used, more vendors are likely to publish security alerts, said Brian Grayek, chief technology officer at Preventsys, a vulnerability management company in Carlsbad, Calif. "I think you are going to see a floodgate of patches open," he said.

Microsoft also uses Kerberos, but a homegrown version that is not affected by the flaws.

Both bugs affect Kerberos 5 Release 1.4.1 as well as earlier versions, according to MIT.

Independent security-monitoring company Secunia rates the issues "highly critical," its second most serious rating. The French Security Incident Response Team, or FrSIRT, deems the bugs "critical," its highest ranking.

Preventsys' Grayek agreed that the vulnerabilities are serious but noted that crafting attacks is difficult. "It is going to take somebody with a great deal of knowledge to turn these vulnerabilities into exploits," he said.

This isn't the first flaw in Kerberos. In March, MIT warned of a "serious" bug in the telnet program supplied with Kerberos. Last August, a "critical" flaw was discovered and patched.

Earlier this month a vulnerability in another widely used software component exposed some of the same products to attack. That flaw affects the open-source "zlib" data compression technology. Using a specially crafted file, an attacker could take control over a computer or crash applications that use zlib.

Source.

More in Tux Machines

Google’s Project Ara Open Source Smartphone to Debut in Puerto Rico This Year

Google sold Motorola to Lenovo, but retained the Advanced Research and Projects (ATAP) R&D group that runs the project. ATAP recently showed off a second generation prototype of the Ara phone, and earlier this month, Google announced plans to launch a 2015 pilot program in Puerto Rico. Project Ara has also recently attracted some interesting technology partners, including battery maker SolidEnergy, audio experts Sennheiser, and health accessory designer Lapka. Together with ATAP's Project Tango for developing 3D sensing phones, Project Ara represents Google's vision for the smartphone future. The timing seems right, as the Android smartphone scene is looking a bit moribund compared to hot-ticket technologies like wearables, drones, and home automation. Read more

Jolla Tablet running Linux-based Sailfish OS enters second round on Indiegogo with 64GB model

Finnish startup Jolla is looking to crowdsource a new 64GB version of its tablet on Indiegogo, following the original campaign a few months ago. For those unfamiliar with this project, Jolla aims to bring a new platform to the market with its tablet, which runs a Linux-based operating system called Sailfish OS. Read more

NI to help CERN adopt 64bit Linux

European lab CERN is working to standardise 64bit Linux as the operating system for all if its control systems, according to test firm National Instruments (NI). Read more

LibreOffice 4.4 Released, How To Install/Upgrade In Ubuntu/Linux Mint


libreoffice 4.4 released install in ubunt/linux mint

LibreOffice and open source office suit releasedLibreOffice 4.4 that is said to have the most beautiful changes ever. LibreOffice is a must app that has lots of features that makes office work in Linux easier. Let's see the new features and how we can Install/Upgrade to LibreOffice 4.4 in Ubuntu Vivid  Vervet, Trusty Tahr etc. and Linux Mint Rebecca, Qiana etc.
 
 
 
 
 

Read at LinuxAndUbuntu