Feeds

Red Hat pre-releases major Linux bug details

Doh! Other vendors caught unprepared

  • alert
  • submit to reddit

Boost IT visibility and business value

On the surface, it was just another turn of the endless cycle of software release, hole discovery, and patching: operating system vendor Red Hat issued an advisory Tuesday warning the world about a serious security hole in a file transfer program that comes with Linux, and urged customers to download a patch.

There was just one problem: Red Hat's advisory jumped the gun on what was intended to be a simultaneous multi-vendor release, carefully coordinated by the government-funded Computer Emergency Response Team (CERT), and scheduled for 3 December. Caught off guard, other Linux vendors were rushing Wednesday to finalize their own patches for the hole-- a memory-allocation bug in the ubiquitous Washington University WU-FTPd program.

"The vendors agreed on releasing the information about the flaw... on December 3rd," wrote Roman Drahtmüller, of Linux vendor SuSE, in an email interview. "This timeline was set up for vendors to build and test their packages, which can be a very time-consuming process... If this timeline is broken, distributors... run into a difficult situation, since their users can't download the update packages."

The hole is the result of a programming error in the portion of WU-FTPd that processes file names containing special characters. BindView's Matt Power discovered in April that the server would crash if presented with the file name '~{', but the program's maintainers believed the bug could not be exploited.

Then researchers at Argentina-based Core Security Technologies discovered the bug themselves in November, and proved that careful manipulation of the bug yields remote root access to vulnerable systems.

To exploit the bug, attackers must first log in to a host's FTP server. But on many systems, limited anonymous FTP access is enabled by default.

The hole affects thousands of users of virtually every Linux release. Because of the wide implications, Core, working with CERT, and, at one point, SecurityFocus' "Vulnerability Help" team, arranged a coordinated release with Caldera, SuSE, TurboLinux, Debian, Red Hat, and other Linux vendors, so that patches would be available for every distribution simultaneously. December 3rd was picked for the release.

That plan went out the window Tuesday, when Red Hat unilaterally issued its own advisory.

"Everybody else, they look like jerks, and they have to scramble to get fixes," said an irate Ivan Arce, CTO of Core Security Technologies. "The only fixes now out publicly are Red Hat's."

Red Hat apologized to other vendors Tuesday night.

"It was a big mistake," says Mark Cox, Red Hat's senior director of engineering. "The package was ready to go live, and we were holding off until the date this was going to hit." Instead, a Red Hat administrator accidentally swept up the advisory with other, unrelated updates sent out Tuesday.

The company has changed its release process to store a 'not-before date' with its pending releases, says Cox. "It's not going to be possible to release something before that date, so we make sure this doesn't happen again. It's not a very good thing."

Despite the snafu, Cox says coordinated releases have worked well for the Linux community in the past. "I don't think it shows any sort of inherent problems in that process."

The FBI's National Infrastructure Protection Center (NIPC) issued an advisory on the hole Wednesday afternoon, and warned that attacks may already be underway. "It is believed that an exploit, leveraging this vulnerability for Linux systems, is already circulating in the hacker community," reads the advisory.

© 2001 SecurityFocus.com, all rights reserved.

Boost IT visibility and business value

More from The Register

next story
The Return of BSOD: Does ANYONE trust Microsoft patches?
Sysadmins, you're either fighting fires or seen as incompetents now
Microsoft refuses to nip 'Windows 9' unzip lip slip
Look at the shiny Windows 8.1, why can't you people talk about 8.1, sobs an exec somewhere
Munich considers dumping Linux for ... GULP ... Windows!
Give a penguinista a hug, the Outlook's not good for open source's poster child
Intel's Raspberry Pi rival Galileo can now run Windows
Behold the Internet of Things. Wintel Things
Linux Foundation says many Linux admins and engineers are certifiable
Floats exam program to help IT employers lock up talent
Microsoft cries UNINSTALL in the wake of Blue Screens of Death™
Cache crash causes contained choloric calamity
Eat up Martha! Microsoft slings handwriting recog into OneNote on Android
Freehand input on non-Windows kit for the first time
prev story

Whitepapers

Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
7 Elements of Radically Simple OS Migration
Avoid the typical headaches of OS migration during your next project by learning about 7 elements of radically simple OS migration.
BYOD's dark side: Data protection
An endpoint data protection solution that adds value to the user and the organization so it can protect itself from data loss as well as leverage corporate data.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?