New York Web Design News September 20 2003, the latest breaking New York Web design news brought to you by,
Web Designs Now,Website Designs Now,New York Web Design Homepage,Web Design Services for New York, Connecticut, Long Island,New York Web Design Client Testimonials,Website Portfolio of New York Web Design, About this New York Web Design Firm,Contact this New York Web Design Firm

OpenSSH & Sendmail Security Flaws
Web Design & Technology News, September 20, 2003

New Adobe Creative Suites
Google Ads Milestone
VeriSign Settles w/ FTC
OpenSSH Patches 2nd Flaw
Google's Local Search
Yahoo! Product-compare
VeriSign Defies ICANN
ICANN Responds to VeriSign
ISPs Limit Transfer Volume
Open-souce Security Flaws
VeriSign's SiteFinder Sued
DB2 Linux Security Flaw
MSFT Adopts Wi-Fi 802.11g

VeriSign's 404 Handling
Sun SW Intros@Confab
Symantec Security Servers
VCs Get More for Their $
Bright Outlook for HDDs
More Holes in MSFT Windows
New Macromedia Web Tools
IE Patch Doesn't Work
Scaled-down Intel Itanium-IIs
Lycos E-mail Troubles
IBM+Borland Challenge MSFT
Verizon Puts $1B into 3G
DOJ OKs Yahoo+Overture

More Web Design News:
2008 Current News
2008 July
2008 June
2007 June
2007 May
2007 March
2006 November
2006 September
2006 August
2006 July
2006 June
2006 May
2006 April
2006 March
2006 February
2006 January
2005 December
2005 November
2005 October
2005 September
2005 August
2005 July
2005 June
2005 May
2005 April
2005 March
2005 February
2004 March
2004 February
2004 January
2003 December
2003 November
2003 October
2003 September
2003 August
2003 July
2003 June
2003 March - May



September 20, 2003

Although MSFT (Microsoft) Windows vulnerabilities get most of the headlines, researchers this week identified vulnerabilities in two commonly used open-source software products.
By Ina Fried

The more serious of the vulnerabilities affects Sendmail, an open-source program for managing e-mail. The vulnerability lies in the way the e-mail server software parses e-mail headers, according to Dan Ingevaldson, engineering manager for Internet Security Systems in Atlanta.

"It's an extremely serious vulnerability," Ingevaldson said, adding that computer attackers could probably exploit it. It is less clear, he said, whether a separate flaw in OpenSSH, also discovered this week, can be exploited.

"It may remain theoretical, it might prove to be exploitable," he said of the flaw in OpenSSH, which is used by network managers to log in remotely and gain encrypted access to computers and other networked devices.

Although it is not clear whether the OpenSSH vulnerability is exploitable, it would be serious if it were. The flaw occurs before authentication, meaning a user would not need privileges to log on to the machine to run the exploit, said Jason Rafail, an Internet security analyst with Carnegie Mellon University's CERT Coordination Center.

CERT issued an advisory on Tuesday for the OpenSSH vulnerability and another on Thursday for the Sendmail flaw.

The OpenSSH issue affects versions before 3.7.1 and occurs as a problem in the way the software stores chunks of data using storage areas called buffers. Cisco said it has products that are affected, while Red Hat, Sun Microsystems and IBM's AIX Toolbox for Linux all use versions of OpenSSH that could be vulnerable.

The Sendmail flaw affects versions before 8.12.10. HP, IBM and Red Hat are among the software makers that use Sendmail and whose products could be affected.

Both pieces of software are commonly used at large companies, making them an attractive target to hackers, Ingevaldson said. "Hackers like to attack high-value targets," he said.

Word of these flaws come amid concern that virus writers may create new bugs based on Windows vulnerabilities disclosed last week.

The latest flaws add to the debate over which is more secure--commercial software, such as that from MSFT, or open-source software, such as Linux.

"In any given year there have been just as many vulnerabilities in the open-source community as there have been with MSFT," Ingevaldson said.

It is difficult to compare the two, he said, but he noted that developers of both use similar tools to write their software and face similar challenges in dealing with hundreds of thousands or millions of lines of code.

With companies blocking all but a handful of the 65,000 available network ports, Ingevaldson said that hackers tend to target the infrastructure for things like e-mail and Web pages, which are allowed to enter a network.

"The open-source guys and the big commercial vendors are dealing with the same problem," Ingevaldson said.

Web Designs Now
Back to the Top


 © Copyright 2007, All rights reserved  |  Privacy Web Design Forums  |  Web Design News  |  Advertise  |  About Us  |  Contact Us  |  W3C HTML 
 Related Websites: New-York-WebDesign.com