All the latest UK technology news, reviews and analysis

Sun denies Unix flaw

by John Geralds in Silicon Valley

20 Nov 2001

Be the first to comment

  • Tweet this

A number of Unix vendors have been alerted to a security flaw, but Sun Microsystems is refusing to acknowledge that any problem exists.

Six vendors, including IBM, Hewlett-Packard and Sun, have been alerted to a vulnerability that ships with several Unix systems, which could allow a malicious attacker to take control of an affected system.

Internet Security Systems (ISS) identified the Unix vulnerability about a month ago, and the company warned that the serious weakness could be found in six Unix vendors' systems. ISS and CERT (Computer Emergency Response Team) issued an advisory about the problem.

While Caldera, Compaq and IBM said they had a patch for the problem, HP disagreed on the versions of its Unix flavour that needed the patch.

Sun said there wasn't a problem at all but it would investigate further, and SGI said it had acknowledged the CDE vulnerabilities and was currently investigating.

The affected software includes several versions of HP's HP-UX, IBM's AIX, Sun's Solaris, Caldera OpenUnix and UnixWare, and Compaq's Tru64 Unix.

"This vulnerability affecting CDE is, by default, on most Unix servers and desktops," said Dan Ingevaldson, ISS team leader for uncovering security vulnerabilities.

He said that no known hacker tool has been posted to exploit the attack, but pointed out that the vulnerability is serious enough that ISS is urging companies with Unix systems from the six vendors to check with them about patch availability.

According to an advisory from CERT, the vulnerability exists in a function used by the Common Desktop Environment (CDE). Because of an error in the way requests from clients are validated, hackers could manipulate data and cause a buffer overflow.

CERT said many common Unix and Linux systems ship with CDE installed and enabled by default. Some Unix vendors have provided information, which is available at CERT's website.

CERT advised that until patches were available, users could lessen their exposure by limiting or blocking access to the Subprocess Control Services from untrusted networks.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

99%

0%

1%

0%

0%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Network Support Engineer Up To £40k

(Roc Search - Network Support Engineer, 2nd line, 3rd...

3rd Line Engineer / Infrastructure Engineer - VMware, Server,

3rd Line Engineer / Infrastructure Engineer - Berkshire...

SQL Server DBA - Database Administrator - MySQL Suffolk - £50k

MySQL SQL SERVER DBA / Database Administrator - Online...

PMO Analyst - Banking

PMO Analyst - Banking Client A financial organisation...

To send to more than one email address, simply separate each address with a comma.