HardwareHeaven.com

HardwareHeaven.com

Looking for the skin chooser?
 
 
  • Home

  • Hardware reviews

  • Articles

  • News

  • Tools

  • Gaming at HardwareHeaven

  • Forums

 

Go Back   HardwareHeaven.com > Forums > News > Other Tech News > Submit News


Submit News If you would like to submit news to us, please post it in this forum.

Closed Thread
 
Thread Tools
Old Dec 22, 2005, 06:03 AM   #1
HardwareHeaven Senior Member
 
edperks's Avatar
 
Join Date: May 2002
Location: Southern Illinois
Posts: 780
Rep Power: 0
edperks is on a distinguished road
System Specs

Donator
Symantec Antivirus Software Open To Attack

Symantec Antivirus Software Open To Attack

The bug, which could result in a completely compromised machine, remains unpatched, although Symantec has issued an advisory.

Symantec's line of anti-virus software is vulnerable to attack, a prominent security researcher revealed Tuesday. The bug is currently unpatched, although Symantec has issued an advisory.

The vulnerability, which was discovered and reported by Alex Wheeler, is in how Symantec's AntiVirus Library, part of all the Cupertino, Calif.-based security giant's anti-virus products, handles RAR compressed files. RAR files are created by the WinRAR compression utility, developed and sold by RarLab.

The bug, labeled as "Highly critical" by Danish vulnerability tracker Secunia and "High" by Symantec itself, can cause a heap overflow, which then may let an attacker execute additional code. Bottom-line: the bug could result in a completely compromised machine.

"The issues can be leveraged remotely to gain complete control over the affected system," Symantec wrote in an alert Tuesday morning to customers of its DeepSight Threat Management System.

All editions of Symantec's Norton Internet Security and Norton AntiVirus, including AntiVirus for the Macintosh, are at risk, as are other products which include the Library. Those include such enterprise-specific lines as AntiVirus Corporate Edition, Brightmail Anti-Spam, Client Security, and Gateway Security.

Symantec has not issued a patch for the vulnerability, but the DeepSight alert recommended that users disable scanning for RAR files

Wheeler is well known among researchers for his probing of security software weaknesses. Earlier in 2005, he disclosed a slew of vulnerabilities in software from major vendors like McAfee, Kaspersky Labs, F-Secure, and Trend Micro. All the bugs he has discovered involve how the various anti-virus scanning engines handle compressed files. This is the second scanning vulnerability Wheeler has uncovered in Symantec's product line. In February, while working with Internet Security Systems, a Symantec rival, he announced a bug in how Symantec's scanning engine could be hacked as it sniffed through UPX-formatted files.
edperks is offline  


Old Dec 22, 2005, 08:10 AM   #2
HardwareHeaven Extreme Member
 
The_Neon_Cowboy's Avatar
 
Join Date: Dec 2002
Location: U.S.A.
Posts: 16,009
Rep Power: 92
The_Neon_Cowboy is a jewel in the roughThe_Neon_Cowboy is a jewel in the roughThe_Neon_Cowboy is a jewel in the rough
System Specs

disable scanning for RAR files = will welcome welcome to infection with virues/threats too
__________________
The_Neon_Cowboy is offline  
Old Dec 22, 2005, 03:19 PM   #3
Int'l Fish Liaison
 
Vikingod's Avatar
 
Join Date: Jul 2004
Location: By the light of lamp I sit and type...
Posts: 16,197
Rep Power: 112
Vikingod has a divinity and aura the likes we have never seenVikingod has a divinity and aura the likes we have never seenVikingod has a divinity and aura the likes we have never seenVikingod has a divinity and aura the likes we have never seenVikingod has a divinity and aura the likes we have never seenVikingod has a divinity and aura the likes we have never seenVikingod has a divinity and aura the likes we have never seenVikingod has a divinity and aura the likes we have never seenVikingod has a divinity and aura the likes we have never seenVikingod has a divinity and aura the likes we have never seenVikingod has a divinity and aura the likes we have never seen
System Specs

Modified link to point to original post.

please discuss here.

Last edited by Iria; Dec 22, 2005 at 03:56 PM.
Vikingod is offline  
Closed Thread

Thread Tools