ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Industry watch Toolkit

Linux users urged to patch file-sharing flaw

Published: 18 Mar 2003 09:21 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The open-source community is pushing customers to patch their systems and close a hole in a software component that allows Windows programs to store and retrieve files on Linux and Unix servers.

Known as Samba, the popular software can be found on many workstations and servers running any one of the variety of flavours of Linux and Unix, including systems running Apple OS X. Members of the Samba team planned to announce the vulnerability on Tuesday, but they released information over the weekend because some believed a Web site break-in in Germany may have been attributed to the software.

"We know of one site that may have been compromised by this," said Jeremy Allison, co-author of Samba. "That's what precipitated the release."

Several Linux editions -- including Debian, Gentoo, and SuSE -- released patches for the problem. Apple Computer noted in an advisory that Samba is not enabled by default with Mac OS X and Mac OS X Server, but the company plans to issue a patch for version 10.2.4. Red Hat hasn't yet released a patch but will do so soon, the company said in a statement.

The popular software also is used by many file-server and print-server network appliances that are based on the Linux operating system. The danger for these is somewhat lessened, however, because people have been regularly warned that running the software on a computer connected to the Internet is dangerous.

"You would have to be crazy to run this over the Internet," Allison said. The Windows file-sharing protocol, known as the Server Message Block, has been a key weakness in PCs connected to the Internet in the past, because people haven't always known to turn the feature off or use a firewall to protect against intrusions. In general, Linux users tend to be more savvy and know to be careful on computers that have the feature turned on, Allison said.

The flaw occurs in the code that reassembles data that the software receives from the Internet, according to the advisory. By sending the server a specially crafted data packet, an attacker could overload the memory used by the Samba software and cause the application to run code of the intruder's choice.

While the problem was spotted by a security team at German Linux software company SuSE last week, the problem apparently was leaked by someone who had access to the Samba source code. Still, Roman Drahtmueller, head of security for SuSE, stressed that finding the problem during a code review gave companies time to respond.

"If you are going to have a flaw of this magnitude that is the best way to catch it," he said. "That's a great advantage of open source... People are able to look at the code and check its security."


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Security News Section.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
54 out of 123 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:






Related Jobs

Do you love technology?? Are you a Linux/ Unix Administrator??

Do you love technology? Are you a Linux/ Unix Administrator? Are you looking for a job to make you get out of bed in the morning? SO do you want to ...

System Administrators/ West London/ 40k / Linux/ Unix/ Oracle/ MYsql/

Are you a Senior Systems Engineer/ Unix/ Linux/ Windows/ DNS/ Webmail/ Server. IS training and career progression important to you ? Do you want to ...

Junior NOC Engineer Windows/ Linux/ Unix/ Global Giant, 30k

Junior NOC Engineer Windows/ Linux/ Unix/ Global Giant, 30k My client is currently looking for a number of Junior NOC Engineers to join the global ...

Featured Talkback

When all is said, if Microsoft produce the best product people will buy it and thats a good thing. If people have to buy their product because no one else can produce an alternative, only because interoperability protocols are kept secret, then thats a bad thing.

By: pround

Read full story:
EU court crushes Microsoft's antitrust appeal