13 Aug 2002
Security watchers have warned of a major vulnerability affecting multiple flavours of the Unix operating system.
Yesterday security firm Entercept, in conjunction with Cert, released details of a remotely exploitable vulnerability in the Common Desktop Environment (CDE)ToolTalk database server - part of the standard graphical interface on all commercial Unix platforms.
Further reading
According to the warning an attacker could use a specially crafted argument in a Remote Procedure Call (RPC) to exploit a vulnerability in the ToolTalk server. The exploit could be used to remotely execute arbitrary code on the target machine, or cause a denial of service.
The severity of the threat is compounded by the fact that the ToolTalk database server typically runs with root privileges, meaning that malicious code would be executed at the highest level.
Entercept advises enterprises to deploy vendor patches as soon as possible. A number of major Unix distributors, such as Caldera, IBM and Sun, are planning to release patches in the very near future. Others are still looking at the possible impact of the vulnerability.
Latest stories from Security
Related articles
Related jobs
Poll
What is the most important IT priority for your company this year?
Sneak peek at the forthcoming glass-based machine
Connect with V3.co.uk
This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes
Why good data management at all levels is essential in the modern business (video, 6mins)
FX Technical Implementation Consultant (Business Analyst...
IT Support Analyst required by Leyland, Lancashire Software...
A talented PHP / Web Developer is required for a web...
Software Developer ( .NET, C#, VB6, SQL) needed. This...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?