ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Industry watch Toolkit

Security flaw hits Windows, Mac, Linux

Matthew Broersma ZDNet.co.uk

Published: 07 Aug 2002 11:54 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Security researchers have warned of a flaw in communications software that could allow attackers to take over computers running Windows, Unix-based operating systems and Mac OS X, as well as Kerberos authentication systems.

The problem is widespread because it affects some implementations of XDR (external data representation) libraries, used by many applications as a way of sending data from one system process to another, regardless of the system's architecture. The affected libraries are derived from Sun Microsystems' SunRPC remote procedure call technology, which has been taken up by many vendors.

The Computer Emergency Response Team (CERT), a security network based at Carnegie Mellon University, warned on Tuesday that systems using the affected code should immediately apply patches or disable the affected services.

A function in Sun's XDR library contains an integer overflow that can lead to buffer overflows, according to CERT security researchers Jeffrey Havrilla and Cory Cohen. These buffer overflows can allow an attacker to crash the system, execute malicious code or steal sensitive information, Havrilla and Cohen said.

The problem also affects the administration system of Kerberos 5, a widely-used authentication tool, which could allow attackers to gain control of Kerberos Key Distribution Center authentication functions. This could allow an attacker to gain false authentication with other services. Kerberos is included in Windows 2000.

The MIT Kerberos development team issued a warning and patch on its Web site.

Apple Computer confirmed that its Mac OS X operating system contains the vulnerability, which has been fixed through a recent security update, available through the software's automatic update mechanism.

Several vendors of Unix and Unix-like operating systems, including Red Hat, Debian, FreeBSD, Sun and NetBSD said that their software was affected by the issue, and issued fixes. HP said it was investigating the bug's impact.

Microsoft said it is still investigating how Windows is affected by the problem.

The relevant patches are available from the companies' Web sites, or through the CERT advisory on its Web site.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Viruses and Hacking News Section.

Have your say instantly, and see what others have said. Go to the Security forum.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
67 out of 103 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:









Related Jobs

AIX systems administrator- Fife- Circa- 40,000

Providing Unix technical expertise, guidance, installing and configuring Unix (AIX), installing software patches, develop and maintain scripts and ...

Technical BA with Interest Rate Derivatives experience

The client seeks a BA who is comfortable with investigating protocols and familiar with XML interfaces and the formatting of these. Technical BA with ...

Commodities - Application Support Analyst - 50k+

Some of the activities will include investigating / resolving the application support teams issues and also user queries and training. My Client is a ...

Discussions

harpless harpless

interesting..

Friday 16 May 2008, 4:06 PM

3 comments
harpless harpless

The game's up for Vista

Friday 16 May 2008, 3:48 PM

1 comment
ator1940 ator1940

Most secure version of Windows

Friday 16 May 2008, 1:28 PM

1 comment

Featured Talkback

When all is said, if Microsoft produce the best product people will buy it and thats a good thing. If people have to buy their product because no one else can produce an alternative, only because interoperability protocols are kept secret, then thats a bad thing.

By: pround

Read full story:
EU court crushes Microsoft's antitrust appeal