ie8 fix

Linux and Open Source

Steven J. Vaughan-Nichols & Paula Rooney

Code Red for XML open source

By | August 6, 2009, 7:03am PDT

Summary: Codenomicon said it found the issues early this year while developing a product for XML testing, and has already been working with Finland’s CERT-FI on remediation.

In a sign of things to come, Codenomicon has issued an alert against “multiple critical security issues in XML libraries,” which include libraries from Sun, Apache, Python and GNOME.

Codenomicon said it found the issues early this year while developing a product for XML testing, and has already been working with Finland’s CERT-FI on remediation.

Recommendations and patches are already going out. (I first found this cute little guy in 2004, while I was blogging for Corante. A now extinct firm called Irenecrafts was offering instructions on making them.)

Both ZDNet’s UK security team and our own Joe McKendrick have been putting out the word, but it’s also important to note where we are in terms of Bruce Schneier’s famous “window of exposure” chart, first published in the year 2000.

The announcement of a vulnerability is a virus’s second level of fame. You know, who’s virus, get me virus, get me something like virus, get me young virus, and who’s virus. An announcement alerts virus writers to a vulnerability, and exploits follow, meaning the risk to users immediately starts jumping.

The peak moment of risk comes when a vendor discloses a patch, but it does not start declining until after users install the patch.

All this means that we are now entering the key window of vulnerability to this problem, and that window closes only after all your XML libraries have been updated.

If you own any of the following libraries you need to be alert and ready to patch:

  • Python libexpat
  • Apache Xerces
  • Sun JDK and JRE 6 Update 14 and earlier
  • Sun JDK and JRE 5.0 Update 19 and earlier.

Not only will servers and PCs be vulnerable until patches are installed, but so will embedded systems and mobile devices.

Sun says it has patched JRE 6 Update 15 and JRE 5 Update 19 but warns it has no workaround for earlier versions, so this may be around a while. Xerces got out a patch in June and one is in process for Python.

Kick off your day with ZDNet's daily e-mail newsletter. It's the freshest tech news and opinion, served hot. Get it.

Topics

Dana Blankenhorn has been a business journalist for 30 years, a tech freelancer since 1983.

Disclosure

Dana Blankenhorn

Dana Blankenhorn has been a journalist, writer and part-time futurist for over 30 years.

At the present moment I run only a personal blog in addition to my ZDNet open source blog.

DanaBlankenhorn.Com has the subtitle The War Against Oil. In the past I have used it to write about political history, e-commerce, personal matters, some ideas related to open source, and The World of Always On, which is the idea of using sensors, motes and RFID to turn WiFi links into platforms for applications which live in the air.

My IRA account at Schwab holds a few tech shares, most notably some Intel and Applied Materials, but there are no open source companies in it. I don’t even own any CBS stock.

Biography

Dana Blankenhorn

Dana Blankenhorn has been a business journalist for nearly 25 years and has covered the online world professionally since 1985. He founded the Interactive Age Daily for CMP Media, and has written for the Chicago Tribune, Advertising Age's "NetMarketing" supplement, and dozens of other publications over the years.

Related Discussions on TechRepublic

Did you know you can take part in these discussions with your ZDNet membership?
4
Comments

Join the conversation!

Just In

RE: Code Red for XML open source
zakkiromi Updated - 19th May 2011
Not only will servers and PCs be vulnerable until patches are installed, but so will embedded systems and mobile devices. code
0 Votes
+ -
Despite the eyes of millions of altruistic losers, horrific security are streaming through every day. Or maybe all the losers are so focused on developing another replacement desktop, that they don't have time for security. Or most likely, they're visting their hero Reiser in prison. Clueless dopes, keep doing volunteer work for billion dollar corporations, they really do appreciate free labor.
0 Votes
+ -
wow what a intelligent post my god help us
Quebec-french 6th Aug 2009
full of proof no insult what so ever ....
a masterpiece of clarity and more

you must be a member of mensa or or your own
group (redneck for a better tomorow dug in mud
)

Please keep inlighting us sir.. Us few ,happy
few .


Once again we have a clear reprensentation of
high brain power

Sir i salute you and your intelligence
have a glass of moonshine

0 Votes
+ -
Abraham Lincoln once said,"Sometimes it is better to remain silent and have people think you a fool, than to speak and remove any doubt."
0 Votes
+ -
RE: Code Red for XML open source
zakkiromi Updated - 19th May 2011
Not only will servers and PCs be vulnerable until patches are installed, but so will embedded systems and mobile devices. code

Join the conversation!

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]
ie8 fix

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity

White Papers, Webcasts, & Resources
ie8 fix