Welcome | Sign In
LinuxInsider.com
Security

Linux Security Holes Opened and Closed

Print Version
E-Mail Article
Reprints
Linux Security Holes Opened and Closed

While there is an ongoing debate as to the most secure operating system, open-source advocates tout this week's fast-fix response as an example of the security advantages of Linux and other open-source software, which is freely available to users and developers.


Increase Customer Sales with VerticalResponse Email Marketing! Quickly and easily send email newsletters, coupons & sales announcements to your customers – no technical expertise needed. Sign up for your Free Trial today and send 100 emails on us!

In stark contrast to the long waits typical for Windows users wanting to patch software vulnerabilities, recently discovered security weaknesses in the core of the Linux operating system were addressed by major vendors in a matter of just a few days this week.

Two security vulnerabilities in the Linux kernel's memory management code reported by security researcher iSEC were addressed and are now fixed in versions 2.4.25 and 2.6.3 of the Linux kernel. Linux vendors and distributors that have released fix updates include Red Hat, Novell's SuSE Linux and the Debian Project.

Independent security expert Ryan Russell said that regardless of the Windows-Linux debate over which operating system is more secure, there is little doubt that open-source vendors respond more quickly when vulnerabilities emerge.

"One area people can agree on is the open-source vendors do a much quicker job of making patches available," Russell told LinuxInsider. "Open-source vendors are producing the patches quicker. Even if not, as an open-source user, you have the opportunity to fix the problem yourself."

Kernel Breach

iSEC said the vulnerability was identified in the Linux kernel memory management code inside the mremap system call and was caused by a missing function-return value-check. The security firm said the latest issue is not related to another memory-management code vulnerability disclosed earlier this year, which involved incorrect bound checks.

Although security experts downplayed the severity of the Linux holes reported this week, Russell said that because they were kernel-based, they were widespread among all Linux operating systems.

"Being in the kernel makes it a little bit more universal," he said. "If you're running Linux, you do have the vulnerability unless you've upgraded to an updated version."

Open-Source Closure

While there is ongoing debate as to the most secure operating system, open-source advocates tout this week's fast-fix response as an example of the security advantages of Linux and other open-source software, which is freely available to users and developers.

Russell, who likened the latest kernel vulnerability to last year's effort to place a back-door security breach in the Debian Linux kernel, praised Linux vendors for getting the patch out quickly.

"I continue to be impressed by the turnaround time from Linux vendors," Russell said.

The security expert added that because the latest Linux security issue did not affect a part of the operating system that would be the basis for much vendor customization, providing a fix was fairly straightforward.

Proprietary Problems

The Linux vendor response to the security issues compares with a lengthier process for Windows, as Microsoft (Nasdaq: MSFT) has taken as long as eight months to patch severe holes. Russell, who argued that viruses and worms depend largely upon the popularity of a particular operating system, referred to Microsoft's need for more than 120 days from vulnerability disclosure to the fix for it.

Gartner (NYSE: IT) research vice president Richard Stiennon, who criticized Microsoft for making protocols irresponsibly without considering security ramifications, indicated the software giant should aim for a turnaround time of a few weeks at most to provide some kind of defense from vulnerabilities that are made public.

"They have to do it faster," Stiennon told LinuxInsider. "The risk grows astronomically with time."

Still, Stiennon -- who added that Microsoft cannot depend on word of vulnerabilities not getting out -- said Microsoft must ensure the patches it does produce are not introducing other security issues or fouling other Windows applications.

"Frankly, I'd like to see them spend more time developing patches so they don't release buggy patches," he said.


Print Version E-Mail Article Reprints More by Jay Lyman


Talkback: Join the Discussion.
Re: Linux Security Holes Opened and Closed
bangular
Posted 2004-02-20
Patches should only take a few days at the most. Espically when the affected code is almost ...

More by Jay Lyman

Open Source Developer Dumps Novell Over Microsoft Deal
December 26, 2006
A key open source developer, Jeremy Allison, who cofounded the Samba project, has resigned from Novell in protest over the company's recent agreement to enter a collaborative arrangement with Microsoft. The deal has created an uproar in the open source community because it does not treat all recipients of the GPL equally and thus violates the spirit of the license, critics say.
Financial Firms Tap Microsoft for Linux
December 22, 2006
Three major financial institutions are among the first companies to go to Microsoft for Linux services, provided through an agreement the software giant struck with Novell. Although a recent survey showed customer approval of the collaboration, many members of the open source community view Novell's move as sleeping with the devil.
Mozilla Beefs Up Security in Firefox 2.0
December 21, 2006
Mozilla's latest update to its open source Firefox browser includes security measures targeting phishers. Phishing scams that use social engineering techniques to dupe Web surfers into revealing personal financial information have become an effective way for cybercriminals to conduct their nefarious activities on the Internet.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network