Members
  • Total Members: 12818
  • Latest: martin
Stats
  • Total Posts: 28534
  • Total Topics: 8240
  • Online Today: 1020
  • Online Ever: 51419
  • (01. January 2010., 10:27:49)












Author Topic: Latest flaws affect AV giants  (Read 2063 times)

0 Members and 1 Guest are viewing this topic.

Samker

  • SCF Administrator
  • *****
  • Posts: 7206
  • KARMA: 291
  • Gender: Male
  • Whatever doesn't kill us makes us stronger.
    • SCforum.info - Samker's Computer Forum
Latest flaws affect AV giants
« on: 15. May 2007., 15:34:31 »
Symantec, McAfee and CA all patch vulnerabilities.

Three of the biggest names in the security sector, McAfee, Symantec and CA, have all revealed details of flaws in their software which have been discovered and patched in recent months.



The most severe vulnerability was suffered by a wide range of McAfee products, including its flagship VirusScan and Internet Security Suite software. A buffer overflow error in the Subscription Manager ActiveX control could allow code to be executed from malicious websites, resulting in system compromise and remote access. The problem was discovered by iDefense researchers, who describe exploitation of the flaw as 'trivial' in their advisory, here. The issue was patched by McAfee automated updates in late March - some information from McAfee is here, and a Secunia alert, rating the issue 'Highly Critical', is here.

The Symantec issue also involves an ActiveX control, used by some of its Norton products including Norton Internet Security 2006. It could also be exploited by malicious websites to bypass security measures and possibly allow remote access, but is generally considered a less serious threat to users. Another iDefense advisory is here, Symantec's own alert is here and a Secunia summary is here.

iDefense, alongside the Zero Day Initiative (ZDI), was behind the reporting of the CA flaws too, with two buffer-overflow issues affecting some of the company's anti-virus and anti-spyware products. The vulnerabilities could only be exploited from the local system, and may have allowed escalated privileges. Details are here (from CA), here (from iDefense) and here (from ZDI), with another Secunia summary here.

All the reported problems have been fixed by updates and patch releases, which should be applied automatically in most cases. Anyone running the affected products is advised to ensure they are running the latest versions.

Virus Bulletin

Samker's Computer Forum - SCforum.info

Latest flaws affect AV giants
« on: 15. May 2007., 15:34:31 »




 

With Quick-Reply you can write a post when viewing a topic without loading a new page. You can still use bulletin board code and smileys as you would in a normal post.

Name: Email:
Verification:
Type the letters shown in the picture
Listen to the letters / Request another image
Type the letters shown in the picture:
Second Anti-Bot trap, type or simply copy-paste below (only the red letters):www.scforum.info:

Enter your email address to receive daily email with 'SCforum.info - Samker's Computer Forum' newest content:

Terms of Use | Privacy Policy | Advertising