Linux Security Flaw Found
Application, OS vendors prepare patches to plug hole that leaves many Linux programs vulnerable to intrusion.
PCWorld.com and IDG News Service staff
A buffer overflow in a library common to all Linux systems could cause a serious security hole that would let those systems be remotely attacked and taken over, according to a security alert issued by Linux security firm Guardian Digital.
The flaw is in a system library called zlib, used for file decompression in the Linux kernel--so it affects all Linux distributions. Zlib also appears in the GNU Compiler Collection, the Mozilla Web browser, and the X11 windowing system, which provides Linux with a GUI, according to the alert from the Upper Saddle River, New Jersey-based firm.
There are no known exploits for this vulnerability, according to Guardian Digital. No one has reported an intruder breaking into a Linux system through this flaw. However, its security alert refers Linux users to the vendors of their distribution of the operating system for patches or fixes.
An update, zlib 1.1.4, that addresses the vulnerability has already been released by Zlib.org, the Web site where the zlib maintainers post information and updates. The writers urge that any software linking against or derived from an earlier version of zlib should be updated.
Patches Appear
Linux vendor SuSE has already revised its implementation of zlib for use with its products. It recommends applying the patch to versions 6.4, 7.0, 7.1, 7.2, and 7.3 of its distribution, as well as the SuSE Linux Database Server, eMail Server III, Firewall, Linux Connectivity Server, and Linux Enterprise Server 7.
Other vendors of Linux distributions are expected to take advantage of the zlib update and release patches for their applications soon.
A buffer overflow occurs when the working memory assigned to a program or task is deliberately overfilled. A cleverly crafted overflow can cause malicious code to be executed. In this case, programs that use the zlib component for network compression are vulnerable to attack due to the flaw, Guardian Digital said.
In fact, many programs do link to zlib, making the hole potentially quite serious, the alert said. Because of this, many different software packages will have to be updated or patched to fix the vulnerability, according to Guardian Digital.
Familiar Challenge
Competing OS developer Microsoft has also had to deal with potential vulnerabilities from buffer overflow problems recently. No exploits were reported for those holes, either. However, Microsoft issued in December a security bulletin and what it called "critical patches" for several versions of Windows because of flaws that left a Windows PC vulnerable to hackers when it was connected to the Internet.
Microsoft patched a similar hole in its Windows Media Player last November. A buffer-overflow vulnerability could let malicious attackers run programs on a victim's system, Microsoft said at the time.
- Sponsored Resource:Improve your network with the right mix of features, performance and pricing.
- Sponsored Resource:Growing your business requires the right tools. Dell's networking servers can help.
- Sponsored Resource:Thinking about a new Laptop? Lenovo has models to meet everyone's needs.
- Sponsored Resource:Twitter: A how-to guide for using Twitter as a business tool.
- Sponsored Resource:Smartphone security threats are on the rise. Is it time to safegaurd your device?
Print 65% more pages than with refilled inks. Trust Original HP Inks. Hit Print Reliably.
Laptop Showcase
Featured APC Accessories For Your System
10% Off Entire Cart at Online Store
-
APC Back-UPS ES
Safeguards your equipment from damaging surges and spikes that travel along your utility & data lines.
- APC SurgeArrest Performance Highest level of protection for your professional computers, electronics and connected devices, as well as provides surge protection.
People who read this also read:
Best Prices on Security Software
Norton Internet Security 2009 - 1 User/3 PCPrice: $29.97
Norton Internet Security 2009 - 1 User/1 PCPrice: $15.95
Norton 360Price: $25.00
Internet Security 2009Price: $15.99
Norton Internet Security 2009 - 1 User/3 PC, Small BoxPrice: $20.50
Internet Security 2009Price: $24.95
- 2007 Microsoft Office Suites Comparison This paper compares and contrasts four suites of the 2007 Microsoft Office system: Microsoft Office Standard 2007, Microsoft Office Professional Plus 2007, Microsoft Office Enterprise 2007 and Microsoft Office Ultimate 2007. This paper is intended to help organizations understand the applications and capabilities offered, and to identify the suite that best fits their needs.
- Windows Vista Migration: The Business Proposition It's not so much a matter of "if" but "when" for most organizations regarding migration to Windows Vista. Laying the groundwork now for this migration can yield higher ROI than waiting until later. This Computerworld Technology Briefing explains it all.


