CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer
image Security HeadLines: DoS Hole Found in Linux Kernel image
Linux
Anonymous writes "Found this at HackFire

Security experts Thursday warned of a vulnerability in Linux Kernel 2.4 branch, which can be exploited to cause denial-of-service attacks.

The hole in popular open-source operating system was detected in the way the Linux Kernel handles caching of routing information.

By flooding a Linux system with packets with spoofed source addresses, the handling of the cache will consume large amounts of CPU power. This could potentially bring a Linux system offline with a rate of only 400 packets per second by using carefully chosen source addresses that causes hash collisions in the table, according to an security advisory from U.K.-based Secunia.

Secunia rated the flaw as moderately critical and cautioned that it could be exploited to bring a Linux system offline with a rate of only 400 packets per second by using carefully chosen source addresses that causes hash collisions in the table.

Red Hat, the Raleigh, NC, firm that dominates the market for Linux, has issued updated kernel packages to patch Red Hat Linux versions 7.1 through 9. Red Hat said the security hole caused the kernel to use a disproportionate amount of processor time to deal with new packets, resulting in a remote DoS attack.

The Red Hat update also fixes certain non-security related issues.

A temporary workaround could be used to filter traffic using the PREROUTING chain instead of the INPUT chain in iptables, as PREROUTING is performed before the route cache. This would only require minor changes to the filter rules. However, Secunia cautioned that a DoS could still succeed if the system uses iptables (netfilter) to filter traffic. This is even possible with randomly chosen IP addresses that doesn't cause a hash collision, since it just requires a higher rate of packets, the company said.

In addition to Red Hat, vulnerable implementations of the Linux OS include various products from SuSE, Mandrake, Slackware, Gentoo, Debian and Conectiva.

The vulnerability comes in the midst of moves by three tech heavyweights to put Linux under the security microscope. The three firms -- IBM Corp., Oracle and Red Hat plan to work with the open-source community to put Linux up for the Common Criteria certification process.

Common Criteria certification for Linux is seen as a crucial first stem to win commercial approval for Linux among government clients. The U.S. federal government CC approval for any IT product used in national security systems. "
Posted on Thursday, 15 May 2003 @ 13:53:04 UTC by phoenix22 (1281 reads)
[ Trackback ]
image

"Security HeadLines: DoS Hole Found in Linux Kernel" | Login/Create an Account | 0 comments
Threshold
The comments are owned by the poster. We aren't responsible for their content.

No Comments Allowed for Anonymous, please register
 
Login
spacer
Nickname

Password

Security Code: Type Security Code: Usage signifies AUP acceptance
· New User? · Click here to create a registered account.
block bottom
Related Links
spacer
· del.icio.us!
· digg it!
· reddit!
· TrackBack (0)
· Linux.com
· IBM
· PHP HomePage
· MandrakeSoft
· Red Hat
· Debian GNU/Linux
· Slackware
· Linux Kernel Archives
· SuSE
· HotScripts
· W3 Consortium
· Oracle
· More about Linux
· News by phoenix22


Most read story about Linux:
The world's easiest Linux desktop deployment and management - NOW FREE!

block bottom
Article Rating
spacer
Average Score: 0
Votes: 0

Please take a second and vote for this article:

Bad
Regular
Good
Very Good
Excellent


block bottom
Options
spacer

Printer Friendly Page  Printer Friendly Page

block bottom
spacer spacer