News

Microsoft Acknowledges Problem with Services for Unix

Microsoft Corp. this week patched a memory leak in the latest version of its Unix interoperability software that an attacker could exploit to take down Windows NT and Windows 2000 servers.

The patches for Services for Unix (SFU) 2.0 represent the 39th security bulletin out of Microsoft so far in 2001. Like many of the patches issued this year, the bulletin wraps up fixes for a couple of problems.

Services for Unix provides Windows-based implementations of common Unix tools and services and heterogeneous network management tools for administrators in mixed Windows/Unix environments.

Memory leaks in two SFU services, one that implements the Network File System (NFS) and one for the Telnet protocol, could be exploited in a denial-of-service attack, Microsoft acknowledged in the bulletin. Administrators targeted by such an attack would need to reboot to get their servers running properly again.

SFU 1.0 is not affected, nor are the standard Windows implementations for Telnet in Windows NT 4.0 and Windows 2000 servers.

Microsoft notes that the vulnerabilities afford attackers no possibility to usurp administrative control over the server. Nonetheless, the company says system administrators using NFS or Telnet services provided in SFU 2.0 should install the patch, which causes SFU to correctly release memory.

The patch will be included in Services for Unix 3.0.

About the Author

Scott Bekker is editor in chief of Redmond Channel Partner magazine.

Featured

  • Attackers Using Excel Read-Only Files To Obscure Malware

    Attackers can attempt to hide malicious payloads in Excel files sent by e-mail by using a standard Excel feature, according to a Tuesday post by Mimecast researchers.

  • Microsoft 365 Personal and Family Product Unveiled

    Microsoft on Monday announced new "Microsoft 365 Personal and Family subscriptions" to come next month, a new single consumer product providing access to applications such as Excel, PowerPoint and Word.

  • Microsoft Shifting Away from Office 365 Brand Name in April

    Microsoft on Monday announced coming product naming changes, where "Office 365" is mostly getting replaced by the "Microsoft 365" brand.

  • Microsoft Grows Services Amid COVID-19

    Microsoft in a Saturday announcement recapped how its services have been affected by "shelter-in-place" governmental mandates in the last week, providing details on growth stats and prioritizations.

comments powered by Disqus

Office 365 Watch

Sign up for our newsletter.

Terms and Privacy Policy consent

I agree to this site's Privacy Policy.