ZDNet:  Reviews | News | Downloads | Prices

AppsNetworkingSecurityeBusinessHardwarePlatformsIT Products

 Anti-Virus  |  Authentication  |  Encryption  |  Firewalls  |  VPN  |  more...















Resources
IT Product Finder
Special Reports
Downloads
Tech Jobs
White Papers
RFP Center
Letters to the Editor
Subscribe to Newsletters
Events Calendar
Register for Classes
Online Book Library
Contact the Editors
E-mail Publishing
Managed Hosting



Search: 
Sign up for Tech Update Newsletters

Security flaw hits Windows, Mac, Linux
By Matthew Broersma
ZDNet (UK)
August 7, 2002
TalkBack!
E-mail this story!

Printer Friendly


Security researchers have warned of a flaw in communications software that could allow attackers to take over computers running Windows, Unix-based operating systems, and Mac OS X, as well as Kerberos authentication systems.

The problem is widespread because it affects some implementations of XDR (external data representation) libraries, used by many applications as a way of sending data from one system process to another, regardless of the system's architecture. The affected libraries are derived from Sun Microsystems' SunRPC remote procedure call technology, which has been taken up by many vendors.


The Computer Emergency Response Team (CERT), a security network based at Carnegie Mellon University, warned on Tuesday that systems using the affected code should immediately apply patches or disable the affected services.

A function in Sun's XDR library contains an integer overflow that can lead to buffer overflows, according to CERT security researchers Jeffrey Havrilla and Cory Cohen. These buffer overflows can allow an attacker to crash the system, execute malicious code or steal sensitive information, Havrilla and Cohen said.

The problem also affects the administration system of Kerberos 5, a widely-used authentication tool, which could allow attackers to gain control of Kerberos Key Distribution Center authentication functions. This could allow an attacker to gain false authentication with other services. Kerberos is included in Windows 2000.

The MIT Kerberos development team issued a warning and patch on its Web site.

Apple Computer confirmed that its Mac OS X operating system contains the vulnerability, which has been fixed through a recent security update, available through the software's automatic update mechanism.

Several vendors of Unix and Unix-like operating systems, including Red Hat, Debian, FreeBSD, Sun and NetBSD said that their software was affected by the issue, and issued fixes. HP said it was investigating the bug's impact.

Microsoft said it is still investigating how Windows is affected by the problem.

The relevant patches are available from the companies' Web sites, or through the CERT advisory on its Web site.

What action will you take first to guard against this flaw? TalkBack below or e-mail us with your thoughts.


ARTICLES
 FBI warns of hacker attacks

 Fed plea: Stop security leaks

 Big hacker bust

 Why you need the latest round of MS security fixes

PRODUCTS
 RSA Keon UNIX Platform Security 4.5

 ISS BlackICE Defender

 Silicon Defense Sentarus SN2

 Tivoli Intrusion Manager

Visit the Security Update Center

 Newsletters
Tech Update Today
eBusiness Update
Tech Update Weekly
Linux Update
Security Update
Windows 2000/XP Update

All newsletters
FAQ
Manage my newsletters

E-mail this story!
Printer Friendly

 TalkBack: Post your comment here
       Re:   Steve Rosenstein

       Re: Security flaw hits Windows, Mac, Linux  Chris Clawson








ZDNet
Services: IT Jobs | Memory Upgrades | BizTech Library | CNET Back to School Guide | Newsletters

      CNET Networks: Builder | CNET | GameSpot | mySimon | TechRepublic | ZDNet

About CNET Networks 

About Us | Support | Your Privacy | Service Terms | How to Advertise | ZDNet Jobs
 
Copyright © 2002 CNET Networks, Inc. All rights reserved. ZDNet is a registered service mark of CNET Networks, Inc. ZDNet Logo is service mark of CNET Networks, Inc.