ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Online business Toolkit

Distributors stamp on Linux bugs

Will Knight ZDNet.co.uk

Published: 20 Oct 1999 15:58 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Popular Linux distributor Red Hat issued a bug fix Wednesday that will stop users from printing pages they have no access to. The bug was discovered just two days ago.

The speed with which Red Hat has produced the fix contradicts frequent accusations that it takes far longer to develop open source applications than conventional software.

The bug was located in the lpd and lpr programs of Red Hat distributions 4.X to 6.1. They involve bypassing permission checking while carrying out printing jobs. The swift fix of this problem represents not only a triumph for Red Hat but also for the many independent developers that contribute to developing the Linux operating system and Linux software.

It is not all sweetness and light in the open source community however. Security news group Bug Traq uncovered another exploit Wednesday -- affecting both Debian GNU/Linux and Red Hat Linux -- that can enable a user to bypass permissions and read restricted files.

It has emerged that an applet called "xmonisdn", which is built into the XWindows graphical interface of both these distributions and is designed to help users monitor ISDN use, can be manipulated to reveal the contents of restricted files.

Bug Traq contributor Ron Van Daal has developed a script to illustrate this exploit.

Follow-up story

Take me to the Linux Lounge .

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
50 out of 90 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:










Related Jobs

Exception Java Developer Hedgefund Algo Execution Trading - DMA/FIX

Links/messaging protocols for order execution both direct to exchanges and via prime brokers through FIX connectivity. Exception Algorithmic Trading. ...

Equities & FIX Application Support Specialist - Contract

Working knowledge of the FIX protocol (versions 4.0; 4.2 and 4.4). My Client has a requirement for an Equity and Exchange Connectivity Support ...

FIX CONNECTIVITY - LONDON - PERMANENT

FIX Support Engineer with strong client facing skills required for a leading boutique financial software organisation. An in-depth knowledge of FIX ...

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

Featured Talkback

I wonder, who needs .asia domain? I cannot imagine, what would be useful for Microsoft.asia? Toyota.asia? Then let's register .europe (if .eu is too short). Or perhaps Microsoft.southamerica, Dell.australiaandnewzealand, Coca-Cola.africa... Sound funny? Then why not just use the global and country domains? Or perhaps it is time to drop the domains at all?

By: LadyRoot

Read full story:
Businesses advised to register .asia domains