ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Industry watch Toolkit

Font flaw foils Solaris security

Published: 27 Nov 2002 08:53 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A flaw in the software that handles fonts for the desktop interface on Solaris-based workstations and servers could leave the computers open to attack, security experts said late on Monday.

The vulnerability could give hackers and online vandals the ability to take control of Solaris-based systems, according to an advisory released by security software developer Internet Security Systems. Sun Microsystems spokesman Brett Smith confirmed that the company knew of the flaw.

"We are aware of the problem, and we are working on a patch," he said, adding that Sun had been working with ISS on a patch, but problems during testing had delayed the fix. "We are trying to get it up as soon as possible."

The flaw, a memory problem known as a buffer overflow, appears in the X Windows Font Server (XFS) software known as fs.auto, a key component of the Solaris desktop system. However, the problem doesn't just affect workstations, said Jay Dyson, senior security consultant with security software Web site Treachery Unlimited.

"The problem is that it comes turned on with default Solaris," he said. "And 90 percent of the people don't turn it off."

The flaw affects every version of the operating system from Solaris 2.5.1 to Solaris 9 on both Sun's Sparc and Intel's x86 architectures, ISS stated in its advisory. A representative from the Atlanta-based security company was not immediately available for comment.

ISS recommends that administrators turn off the Solaris font software unless it's absolutely necessary. On any computer that needs the software, the company recommends that administrators block the port to keep outside attackers from using the flaw to get control of a computer within the network. A port is a software data channel that applications use to communicate with other computers via a network.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Security News Section.

Have your say instantly, and see what others have said. Go to the Security forum.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
29 out of 64 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:







Related Jobs

Unix SA/Engineer (Solaris,Linux, LVM, Veritas) BANKING

Candidates MUST have worked in a large enterprise environment & in depth knowledge of Sun Solaris & SPARC hardware, Redhat Linux RHEL 3.0 & above, ...

Solaris Systems Administrator 9 and 10 contract London

My Client based in Central London is currently looking for a Solaris Systems administrator with 9 and 10 experience, specifically with configuration ...

UNIX Systems Engineer at Top Financial Co! (Solaris/Red Hat Linux)

Leading Market maker has an excellent position for Unix Engineer with strong Linux and Solaris skills. You well also be managing Linux/Solaris ...

Discussions

harpless harpless

SAP goes big business

Friday 25 July 2008, 6:17 PM

1 comment
pjc158 pjc158

Will Drizzle rain on Sun's MySql

Friday 25 July 2008, 5:30 PM

1 comment
pjc158 pjc158

Show me the money!

Friday 25 July 2008, 5:18 PM

5 comments

Featured Talkback

When all is said, if Microsoft produce the best product people will buy it and thats a good thing. If people have to buy their product because no one else can produce an alternative, only because interoperability protocols are kept secret, then thats a bad thing.

By: pround

Read full story:
EU court crushes Microsoft's antitrust appeal