Red Hat warns of security patch hoax for Linux users
A fake security e-mail is being sent out to users
Computerworld - Linux vendor Red Hat Inc. is warning customers about an e-mail hoax that urges them to download security patches that actually contain malicious payloads.
In a note to customers on its Web site, Red Hat said it "has been made aware that e-mails are circulating that pretend to come from the Red Hat Security Team. These e-mails tell users to download and install malicious updates. These Trojan updates contain malicious code designed to compromise the systems they are run on."
The company said that "official messages from the Red Hat security team are never sent unsolicited" and are always sent from the address secalert@redhat.com. All security messages are also digitally signed using GNU Privacy Guard security keys to prove their authenticity, the Raleigh, N.C.-based company said.
"All official updates for Red Hat products are digitally signed and should not be installed unless they are correctly signed and the signature is verified," the company said.
A spokesman for the company couldn't be reached for comment this morning.
One example of the hoax e-mail is dated Oct. 20 and claims that "Redhat [sic] found a vulnerability in fileutils (ls and mkdir), that could allow a remote attacker to execute arbitrary code with root privileges. Some of the affected linux distributions include RedHat 7.2, RedHat 7.3, RedHat 8.0, RedHat 9.0, Fedora CORE 1, Fedora CORE 2 and not only. It is known that *BSD and Solaris platforms are NOT affected."
The hoax e-mail claims that "the RedHat Security Team strongly advises you to immediately apply the fileutils-1.0.6 patch," which it calls a "critical-critical update."
The hoax e-mail also points the recipient to an alleged Security RedHat mirror Web site where the malicious download, 1.0.6.patch.tar.gz, can be obtained. "Again, please apply this patch as soon as possible or you risk your system and others' to be compromised," the hoax e-mail says.
Read more about Linux and Unix in Computerworld's Linux and Unix Topic Center.


- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Practice Management: Double Billing Rate and Improve Patient Services
- Would you like to double your billing rate and achieve faster payment for services?
Download this customer success story to see how One Health... - Mission Critical Data Explosion and Customer Case Study
- Would you like to double your tier 1 storage capacity while simultaneously reducing your storage footprint?
Download this customer success story to see how... - Protecting Against Database Attacks and Insider Threats: Top 5 Scenarios
- Read this new eBook to learn the top five scenarios and essential best practices for preventing database attacks and insider threats.
- Database Activity Monitoring Is Evolving
- Read the analyst report and learn how you can leverage the core capabilities of a DAP solution for better database security.
- Establishing a Strategy for Database Security is No Longer Optional
- The options for securing increasingly valuable databases are very broad and deep, and can be confusing. This research provides an overview of three... All Linux and Unix White Papers
- Distributed Database Security with Real-time Monitoring
- View this demo and learn how IBM InfoSphere Guardium database activity monitoring can help protect your sensitive data in distributed DBMS environments with...
- InfoSphere Warehouse Packs Demo
- These flash modules make warehousing more tangible and relevant to business users through detailed explanations of the InfoSphere Warehouse Packs.
- Delivery Management -- Extending Lifecycle Management
- Date: Wednesday, June 20, 2012, 1:00 PM EDT
Siloed organizations continue doing the wrong things and doing things wrong, leading to increased costs,... - Leverage automation today to reduce IT complexity
- Date: Tuesday, June 5, 2012, 2:00 PM EDT
Whether your B2B complexity is caused by multiple technologies due to M&A, business or application specific... - Redefine Expectations in the Data Center
- Need to do more with less? Watch this video to learn how HP ProLiant Gen8 servers can help your business deploy servers three... All Linux and Unix Webcasts