📺 Stream EntrepreneurTV for Free 📺

Google and Red Hat Found a Dangerous, Widespread Bug The bug, which dates back to 2008, affects hundreds of thousands of devices and programs that use software derived from the GNU free-software project.

By David Meyer

entrepreneur daily

This story originally appeared on Fortune Magazine

Pexels

Engineers at Google and Red Hat independently found an egregious bug in very widely-distributed computer code library known as "glibc".

The bug, which dates back to 2008, affects hundreds of thousands of devices and programs that use software derived from the GNU free-software project. The products, which range from servers to routers to Internet-of-things devices, are vulnerable when they try to use a certain function to translate web addresses into their underlying, numerical IP addresses.

If an attacker controls the web server or domain name the victim is trying to communicate with, or if someone is intercepting the communications between the victim's device and the server or domain name, it's possible to make the victim's computer crash -- or, with some effort, to even insert malicious code in that machine.

Computers running Windows or Mac OS X or iOS or Android should not be affected.

Google explained in a blog post that one of its engineers had discovered the bug when she found a problem with software she was using for remotely controlling a computer. It turned out that two Red Hat employees were also examining the bug's impact.

Google released a piece of code that proves the vulnerability can crash a victim's computer. It said it has also developed a proof-of-concept for remotely running code on the victim's machine, but it's not releasing that publicly, for obvious reasons.

There is now a patch for the bug, and server administrators should definitely be installing that right away. People using Linux versions such as Canonical's Ubuntu should be moving quickly to protect themselves.

Given the severity of the bug, there are now at least two points worth considering.

Firstly, as Google Chrome security engineer Chris Palmer pointed out, the episode highlights the fact that free-software projects don't always fix their bugs in a timely manner -- it turned out someone first raised this bug last July.

Secondly, we can probably expect to see servers and such get patched quickly, but devices with embedded software -- routers and Internet-of-things devices, for example -- don't typically get updated very often, if at all. Internet-of-things manufacturers in particular have a legendarily lax attitude to security.

If a computer doesn't have a screen attached to it, people tend to forget that it's a computer and needs regular care and attention. In cases like this, that's a problem.

David Meyer is a writer based in Berlin.

Want to be an Entrepreneur Leadership Network contributor? Apply now to join.

Editor's Pick

Collaboration

5 Ways Solopreneurs Can Scale Their Business Through Collaboration

Our culture loves to perpetuate the myth that entrepreneurs must go it alone. But for many, the path to success is found in collaboration.

Business News

Walmart to Lay Off Hundreds of Employees, Relocate Remote Workers Back to the Office

The news comes just a day ahead of the company's highly-anticipated Q1 2024 earnings report.

Side Hustle

These Coworkers-Turned-Friends Started a Side Hustle on Amazon — Now It's a 'Full Hustle' Earning Over $20 Million a Year: 'Jump in With Both Feet'

Achal Patel and Russell Gong met at a large consulting firm and "bonded over a shared vision to create a mission-led company."

Starting a Business

Livestream | Ask NBA All-Star Stephon Marbury About Mental Game, Launching a Business and More!

Join our free livestream on 5/16/24 at 12 PM ET with former NBA All-Star Stephon Marbury and tech CEO Reid Covington to gain their insights on marketing, starting a business and more. You don't want to miss it!

Business News

McDonald's Is Responding to Sky-High Fast Food Price With a $5 Value Meal — But There's a Catch

The news comes as the chain looks to redirect back to customer "affordability."