July 13, 2005 4:45 PM PDT

Flaws could open systems to attack

Two serious security flaws in a technology widely used for network authentication could expose a swath of software products to hacker attack, experts have warned.

The flaws could allow an online intruder to crash or gain access to computers running Kerberos, a freely available authentication technology that was developed by the Massachusetts Institute of Technology.

MIT rates both flaws "critical," according to two advisories released Tuesday. The university also made available patches to fix the problems and stated that exploitation of the bugs by attackers "is believed to be difficult."

Several software makers have already released updates to their products to address the problem. Red Hat, Turbolinux and Gentoo have issued fixes for their Linux versions, for example. Sun Microsystems on Tuesday issued two alerts acknowledging that several versions of Solaris are vulnerable, but it does not have a patch available yet.

Because Kerberos is so widely used, more vendors are likely to publish security alerts, said Brian Grayek, chief technology officer at Preventsys, a vulnerability management company in Carlsbad, Calif. "I think you are going to see a floodgate of patches open," he said.

Microsoft also uses Kerberos, but a homegrown version that is not affected by the flaws.

Both bugs affect Kerberos 5 Release 1.4.1 as well as earlier versions, according to MIT.

Independent security-monitoring company Secunia rates the issues "highly critical," its second most serious rating. The French Security Incident Response Team, or FrSIRT, deems the bugs "critical," its highest ranking.

Preventsys' Grayek agreed that the vulnerabilities are serious but noted that crafting attacks is difficult. "It is going to take somebody with a great deal of knowledge to turn these vulnerabilities into exploits," he said.

This isn't the first flaw in Kerberos. In March, MIT warned of a "serious" bug in the telnet program supplied with Kerberos. Last August, a "critical" flaw was discovered and patched.

Earlier this month a vulnerability in another widely used software component exposed some of the same products to attack. That flaw affects the open-source "zlib" data compression technology. Using a specially crafted file, an attacker could take control over a computer or crash applications that use zlib.

10 comments

Join the conversation!
Add your comment (Log in or register)
Funny, no vile anti MS posts from Linux zealots!
Could it be because of this quote: "Microsoft also uses Kerberos, but a homegrown version that is not affected by the flaws."
Posted by Anon-Y-mous (124 comments )
Reply Link Flag
OS X wasn't mentioned either
And it uses Kerebos as well.
Posted by (464 comments )
Link Flag
I'll take the bait....
....but I'm not a "Linux zealot". In fact, I don't use Linux at all. I do hope that's ok.

As I read the quote with respect to Microsoft, two thoughts came to mind.

First, MicroSoft does skate by some of the security flaws. Statistically, it's bound to happen. The old saying "A stopped clock is still right twice a day" comes to mind.

Second, the fact that MicroSoft uses their own "home grown" version of Kerberos AND by some cosmic quirk they happened to escape these particular flaws, DOES NOT mean that their version is free of flaws.

It's just a matter of time. The table is open....Place your bets
Posted by (63 comments )
Link Flag
Funny, no vile anti MS posts from Linux zealots!
Could it be because of this quote: "Microsoft also uses Kerberos, but a homegrown version that is not affected by the flaws."
Posted by Anon-Y-mous (124 comments )
Reply Link Flag
OS X wasn't mentioned either
And it uses Kerebos as well.
Posted by (464 comments )
Link Flag
I'll take the bait....
....but I'm not a "Linux zealot". In fact, I don't use Linux at all. I do hope that's ok.

As I read the quote with respect to Microsoft, two thoughts came to mind.

First, MicroSoft does skate by some of the security flaws. Statistically, it's bound to happen. The old saying "A stopped clock is still right twice a day" comes to mind.

Second, the fact that MicroSoft uses their own "home grown" version of Kerberos AND by some cosmic quirk they happened to escape these particular flaws, DOES NOT mean that their version is free of flaws.

It's just a matter of time. The table is open....Place your bets
Posted by (63 comments )
Link Flag
give it up
considering the multiple flawes that have been identified in kerberos over the years of which most have not been in MS implementation as MS when it reviewed the MIT implementation identified many of flawes and were then laughed at and abused for making the changes to there implemetation as they claimed it was better. They have been proven right (there implementation has been out there for over 5 years) but all you will see from people is that "just because they haven't found flawes yet doesn't meant they dont't have any".
Posted by (16 comments )
Reply Link Flag
give it up
considering the multiple flawes that have been identified in kerberos over the years of which most have not been in MS implementation as MS when it reviewed the MIT implementation identified many of flawes and were then laughed at and abused for making the changes to there implemetation as they claimed it was better. They have been proven right (there implementation has been out there for over 5 years) but all you will see from people is that "just because they haven't found flawes yet doesn't meant they dont't have any".
Posted by (16 comments )
Reply Link Flag
 

Join the conversation

Add your comment

The posting of advertisements, profanity, or personal attacks is prohibited. Click here to review our Terms of Use.

Inside CNET News

1-2 of 12

Scroll Left Scroll Right

What's Hot

Discussions

Shared

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

Markets

Market news, charts, SEC filings, and more

Related quotes

Dow Jones Industrials (0.00%) 0.00 12,874.04
S&P 500 (0.00%) 0.00 1,351.77
NASDAQ (0.00%) 0.00 2,931.39
CNET TECH (0.00%) 0.00 2,049.14
  Symbol Lookup