Open-source hunt digs up more flaws

A US government-sponsored open-source bug hunt has resulted in more patches and security alerts.

Vulnerabilities have been found and fixed in X Window System and Ethereal, two popular open source software packages, according to Coverity, the maker of the code analysis tools used in the bug hunt.

The X Window System is used as the foundation of the graphical user interface of many Unix and Linux systems, while Ethereal is a sniffer tool used to analyse network traffic.

Several bugs were found in Ethereal, which is used by network administrators and hackers alike. The latest version, released last week, includes fixes for a host of security holes, including several that were identified in the scan. These flaws could allow a full compromise of a system running the vulnerable software, Coverity said. Security monitoring company Secunia deems the Ethereal issues "highly critical."

"Many of these are remotely exploitable," Andy Chou, Coverity's chief scientist, said in an interview on Wednesday. "You can send data packets, exploit it and get whatever access Ethereal is running at."

The flaw identified in X could allow a local, nonprivileged user to gain full, root-level access to a vulnerable computer, Coverity noted. The flaw, for which a patch has been available since March, is rated "less critical" by Secunia.

The bug hunt is part of a three-year "Open Source Hardening Project," dedicated to helping make such software as secure as possible. In January, the US Department of Homeland Security awarded US$1.24 million to Stanford University, Coverity and Symantec to find vulnerabilities in open-source projects.

Developers have been quick to fix many bugs found as part of the program. More than 900 flaws were repaired in the two weeks after Coverity announced the results of its first scan of 32 open-source projects.

Like this article? Click below to send it to your mobile for free!

Advertisement

Talkback 0 comments


ZDNet's CIO Vision Series

Video | Optus CIO Lawrie Turner

In this exclusive video interview, Optus chief information officer Lawrie Turner speaks to ZDNet.com.au about being the IT head for Australia's number two telco.

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Jude Willis Gutless studios have the wrong target
    I have one word for the Australian Federation Against Copyright Theft (AFACT). Gutless.
  • Array NBN needs workers on board
    Without consensus on labour issues, the eventual winner of the NBN may end up as little more than a lame duck and a cashed-up symbol of the conflict between the desire for progress and the lack of mechanisms to deliver it.
  • Array D'Ascenzo: Read p23 of security review
    Following yesterday's admission by the Australian Taxation Office that its courier had lost a CD containing the details of 3,000 self-managed super funds, it wants to review how it handles information. My suggestion: go back to the review completed in April.
  • More blogs »

Tags

Back to top

Featured