If geeks love it, we’re on it

Security Pros Warn Of Critical Flaws In Kerberos

Security Pros Warn Of Critical Flaws In Kerberos

Vulnerabilities in a technology widely used for network authentication have left computers running Unix, Linux and Apple Computer’s Mac OS X potentially open to attack.

The flaws could allow an online intruder to gain access to computers running a security feature known as Kerberos. The vulnerabilities, found by the developers at the Kerberos Team at the Massachusetts Institute of Technology, should be patched as soon as possible, Sam Hartman, engineering lead for the team, said Wednesday. “I would not expect this to lead to a worm,” Hartman said. “Most sites will patch it because patching is easy to do. Whereas, if you do have a compromise, it is a lot of work to recover.”

Source: c|net

Comments

  1. primesuspect
    primesuspect Funny how they don't mention that Windows 2000 and up use Kerberos as well.....
  2. QCH
    QCH For all of our Telnet connections from Windows OS to UNIX, we use MIT's Kerberos Leash32 2.501... I'll be watching MIT for the fix!!!!

Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!